Debian 10222 Published by

A connman security update has been released for Debian GNU/Linux 10 to address a remote information leak vulnerability and a remote buffer overflow vulnerability.



DSA 4847-1: connman security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-4847-1 security@debian.org
  https://www.debian.org/security/ Salvatore Bonaccorso
February 08, 2021   https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : connman
CVE ID : CVE-2021-26675 CVE-2021-26676

A remote information leak vulnerability and a remote buffer overflow
vulnerability were discovered in ConnMan, a network manager for embedded
devices, which could result in denial of service or the execution of
arbitrary code.

For the stable distribution (buster), these problems have been fixed in
version 1.36-2.1~deb10u1.

We recommend that you upgrade your connman packages.

For the detailed security status of connman please refer to its security
tracker page at:
  https://security-tracker.debian.org/tracker/connman

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:   https://www.debian.org/security/