Lucene search

K
ibmIBMBFD93B51080EB57C20D32C7009F5020102FA6D413B05BE55340AC1B4C088C311
HistoryJun 18, 2018 - 1:38 a.m.

Security Bulletin: A vulnerability in bluez affects PowerKVM

2018-06-1801:38:35
www.ibm.com
13

0.005 Low

EPSS

Percentile

76.6%

Summary

PowerKVM is affected by a vulnerability in bluez. IBM has now addressed this vulnerability.

Vulnerability Details

CVEID: CVE-2017-1000250**
DESCRIPTION:** BlueZ could allow a remote attacker to obtain sensitive information, caused by an error in the SDP server. By sending SDP request packets, an attacker could exploit this vulnerability from the bluetoothd process memory.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/131859 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

PowerKVM 3.1

Remediation/Fixes

Customers can update PowerKVM systems by using “yum update”.

Fix images are made available via Fix Central. For version 3.1, see https://ibm.biz/BdHggw. This issue is addressed starting with v3.1.0.2 update 11.

Workarounds and Mitigations

none

CPENameOperatorVersion
powerkvmeq3.1