Lucene search

K
redhatRedHatRHSA-2017:2685
HistorySep 12, 2017 - 2:08 p.m.

(RHSA-2017:2685) Moderate: bluez security update

2017-09-1214:08:48
access.redhat.com
52

0.005 Low

EPSS

Percentile

76.6%

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Red Hat), and pcmcia configuration files.

Security Fix(es):

  • An information-disclosure flaw was found in the bluetoothd implementation of the Service Discovery Protocol (SDP). A specially crafted Bluetooth device could, without prior pairing or user interaction, retrieve portions of the bluetoothd process memory, including potentially sensitive information such as Bluetooth encryption keys. (CVE-2017-1000250)

Red Hat would like to thank Armis Labs for reporting this issue.