CVE-2017-1000250
medium
CVSS v3
6.5
CVSS v2
3.3
VIR risk
6.5
Description
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Predictions
Exploit likelihood
65%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-1000250.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-1000250
Vendor advisory: arch — https://security.archlinux.org/ASA-201709-3
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 5.46-1 |
| debian | bullseye | fixed | 5.46-1 |
| debian | forky | fixed | 5.46-1 |
| debian | sid | fixed | 5.46-1 |
| debian | trixie | fixed | 5.46-1 |
| sles | affected | | |
| arch | fixed | 5.46-2 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| bluez | bluez | {"endIncluding":"5.46"} | |
References
- https://security.archlinux.org/ASA-201709-3
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561
- http://www.debian.org/security/2017/dsa-3972
- http://www.securityfocus.com/bid/100814
- https://access.redhat.com/errata/RHSA-2017:2685
- https://access.redhat.com/security/vulnerabilities/blueborne
- https://www.armis.com/blueborne
- https://www.kb.cert.org/vuls/id/240311
- https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne
- https://access.redhat.com/security/cve/CVE-2017-1000250
- https://security-tracker.debian.org/tracker/CVE-2017-1000250
- https://www.suse.com/security/cve/CVE-2017-1000250.html
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.