Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "libpulse-dev"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "libpulse-mainloop-glib0"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "libpulse0"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "libpulsedsp"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-esound-compat"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-bluetooth"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-droid"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-gconf"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-jack"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-lirc"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-raop"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-trust-store"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-x11"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-module-zeroconf"
},
{
"binary_version": "1:8.0-0ubuntu3.14",
"binary_name": "pulseaudio-utils"
}
]
}