MGASA-2017-0350
Dashboard / Vulnerabilities / MGASA-2017-0350
Summary: Updated bluez packages fix security vulnerability
Details: An information-disclosure flaw was found in the bluetoothd implementation of the Service Discovery Protocol (SDP). A specially crafted Bluetooth device could, without prior pairing or user interaction, retrieve portions of the bluetoothd process memory, including potentially sensitive information such as Bluetooth encryption keys (CVE-2017-1000250).
References: https://advisories.mageia.org/MGASA-2017-0350.html, https://bugs.mageia.org/show_bug.cgi?id=21698, https://access.redhat.com/security/vulnerabilities/blueborne, https://access.redhat.com/errata/RHSA-2017:2685
Affected packages
Package
Name: bluez
Purl: pkg:rpm/mageia/bluez?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
