2017-06-01 19:31:48

by gw rdk

[permalink] [raw]
Subject: Re: CVE's CVE-2016-9797 to 9804, CVE-2016-9918

Hi =E2=80=94

We'd like to update our bluez - can you tell me if these vulnerability =
reports were addressed? They aren't specifically called out in the =
change log and a spot check doesn't show, for example, a fix for the =
issue in packet.c=20

Were they determined to be too low-risk? or invalid reports?



Any info appreciated, thanks in advance.
gw (on behalf of customer)


https:// nvd.nist.gov/ vuln/ search/ =
results?adv_search=3Dfalse&form_type=3Dbasic&results_type=3Doverview&searc=
h_type=3Dall&query=3Dbluez





2017-06-02 10:27:41

by Szymon Janc

[permalink] [raw]
Subject: Re: CVE's CVE-2016-9797 to 9804, CVE-2016-9918

Hi,

On 1 June 2017 at 21:31, gw rdk <[email protected]> wrote:
> Hi =E2=80=94
>
> We'd like to update our bluez - can you tell me if these vulnerability re=
ports were addressed? They aren't specifically called out in the change lo=
g and a spot check doesn't show, for example, a fix for the issue in packet=
.c
>
> Were they determined to be too low-risk? or invalid reports?
>
>
>
> Any info appreciated, thanks in advance.
> gw (on behalf of customer)

I'm not sure if those are fixed but this seems to only affect HCI
monitor (btmon) which is our testing/debugging tool.

--=20
pozdrawiam
Szymon K. Janc