BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
BID:100814
CVE-2017-1000250 |Info
BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
| Bugtraq ID: | 100814 |
| Class: | Design Error |
| CVE: |
CVE-2017-1000250 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Armis Labs |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Client Optional 7 Redhat Enterprise Linux 7 Client Redhat Enterprise Linux 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 BlueZ BlueZ 2.25 BlueZ BlueZ 2.19 BlueZ BlueZ 2.15 BlueZ BlueZ 1.24 BlueZ BlueZ 1.23 BlueZ BlueZ 1.17 BlueZ BlueZ 1.16 BlueZ BlueZ 1.12 BlueZ BlueZ 1.5 BlueZ BlueZ 5.46 BlueZ BlueZ 5.42 BlueZ BlueZ 5.41 BlueZ BlueZ 3.34 BlueZ BlueZ 2.20 |
| Not Vulnerable: | |
Discussion
BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
BlueZ is prone to an information-disclosure vulnerability.
Successfully exploiting this issue can allow an attacker to obtain sensitive information that may aid in launching further attacks.
BlueZ 5.46 and prior versions are vulnerable.
BlueZ is prone to an information-disclosure vulnerability.
Successfully exploiting this issue can allow an attacker to obtain sensitive information that may aid in launching further attacks.
BlueZ 5.46 and prior versions are vulnerable.
Exploit / POC
BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
BlueZ CVE-2017-1000250 Information Disclosure Vulnerability
References:
References:
- CVE-2017-1000250 (Redhat)
- BlueZ Homepage (BlueZ)
- The dangers of Bluetooth implementations: Unveiling zero day vulnerabilities (Ben Seri ??& Gregory Vishnepolsky)
- The IoT Attack Vector �??BlueBorne�?� Exposes Almost Every Connected Device (Armis)
- Bug 1489446 - (CVE-2017-1000250) CVE-2017-1000250 bluez: Out-of-bounds heap read (Redhat)
- RHSA-2017:2685 - Security Advisory (Redhat)
- VU#240311 Multiple Bluetooth implementation vulnerabilities affect many devices (CERT)