Skip to content

Directory info disclosure

Low
cschramm published GHSA-3r9p-m5c8-8mw8 Feb 8, 2022

Package

No package listed

Affected versions

<= 2.2.3

Patched versions

2.2.4

Description

Impact

Information disclosure - a user can discover arbitrary files and directories.

Patches

The issue got fixed in blueman 2.2.4.

Workarounds

Remove blueman/plugins/mechanism/Ppp.py from the Python site-packages path. This means that the PPPSupport plugin will not work anymore, but connecting to dialup network services is still supported via the NMDUNSupport module.

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits