Back

MEDIUM

bluez: Out-of-bounds heap read in service_search_attr_req function

Published Sep 12, 2017

Description

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2017
Updated Aug 5, 2024
Reserved Sep 12, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 12, 2017
ENISA EUVD
Assigner mitre
Published Sep 12, 2017
Updated Aug 5, 2024
Exploited since n/a
EUVD-2017-1511