All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-bluez | Sep 21, 2017 | Sep 12, 2017 | |
| Centos_linux | — | centos-upgrade-bluezcentos-upgrade-bluez-alsacentos-upgrade-bluez-compatcentos-upgrade-bluez-cupscentos-upgrade-bluez-debuginfocentos-upgrade-bluez-gstreamercentos-upgrade-bluez-hid2hcicentos-upgrade-bluez-libscentos-upgrade-bluez-libs-devel | Sep 13, 2017 | Sep 12, 2017 |
| Redhat_linux | — | redhat-upgrade-bluezredhat-upgrade-bluez-alsaredhat-upgrade-bluez-compatredhat-upgrade-bluez-cupsredhat-upgrade-bluez-debuginforedhat-upgrade-bluez-gstreamerredhat-upgrade-bluez-hid2hciredhat-upgrade-bluez-libsredhat-upgrade-bluez-libs-devel | Oct 4, 2017 | Sep 12, 2017 |
| Suse | — | suse-upgrade-bluezsuse-upgrade-bluez-cupssuse-upgrade-bluez-develsuse-upgrade-libbluetooth3 | Oct 20, 2017 | Sep 12, 2017 |
| Ubuntu | ubuntu-upgrade-bluezubuntu-upgrade-libbluetooth3 | Sep 13, 2017 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub