MEDIUM
bluez: Out-of-bounds heap read in service_search_attr_req function
Published Sep 12, 2017
6.5
MEDIUMCVSS 3.0
EPSS 7.77%
Description
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
bluez-0:4.66-2.el6_9
Fixed · RHSA-2017:2685
Red Hat Enterprise Linux 7
bluez-0:5.44-4.el7_4
Fixed · RHSA-2017:2685
Red Hat Enterprise Linux 5
bluez-utils
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bluez-0:4.66-2.el6_9 | Fixed | RHSA-2017:2685 |
| Red Hat Enterprise Linux 7 | bluez-0:5.44-4.el7_4 | Fixed | RHSA-2017:2685 |
| Red Hat Enterprise Linux 5 | bluez-utils | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561 x_refsource_CONFIRM
- http://www.debian.org/security/2017/dsa-3972 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/100814 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2685 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-1000250 Issue TrackingThird Party AdvisoryVDB EntryVendor Advisory
- https://access.redhat.com/security/vulnerabilities/blueborne x_refsource_CONFIRMNot Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=1489446 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1511 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000250
- https://www.armis.com/blueborne x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-1000250
- https://www.kb.cert.org/vuls/id/240311 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne x_refsource_CONFIRM
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2017
Updated Aug 5, 2024
Reserved Sep 12, 2017
Link CVE-2017-1000250
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2017-1511 Assigner mitre
Published Sep 12, 2017
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2017-1511