CVE-2017-1000250
Summary
| CVE | CVE-2017-1000250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-12 17:29:00 UTC |
| Updated | 2018-02-17 02:29:00 UTC |
| Description | All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3972-1 bluez | DEBIAN | www.debian.org | |
| Vulnerability Note VU#240311 - Multiple Bluetooth implementation vulnerabilities affect many devices | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Security Bulletin: NVIDIA Tegra Jetson L4T contains multiple vulnerabilities; updates for “BlueBorne” and “Dnsmasq”. | NVIDIA | CONFIRM | nvidia.custhelp.com | |
| BlueZ CVE-2017-1000250 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Blueborne - Linux Kernel Remote Denial of Service in Bluetooth subsystem - CVE-2017-1000251 - Red Hat Customer Portal | CONFIRM | access.redhat.com | Not Applicable |
| CVE-2017-1000250 - Red Hat Customer Portal | MISC | access.redhat.com | Issue Tracking, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| BlueBorne Information from the Research Team - Armis Labs | MISC | www.armis.com | Exploit, Technical Description, Third Party Advisory |
| Synology-SA-17:52 BlueBorne | Synology Inc. | CONFIRM | www.synology.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378253 Virtuozzo Linux Security Update for bluez-cups (VZLSA-2017:2685)