UBUNTU-CVE-2018-5383
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-5383
UBUNTU-CVE-2018-5383
Summary:
Details: Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
References: https://ubuntu.com/security/CVE-2018-5383, http://www.cs.technion.ac.il/~biham/BT/, https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00128.html, https://ubuntu.com/security/notices/USN-4094-1, https://ubuntu.com/security/notices/USN-4095-1, https://ubuntu.com/security/notices/USN-4095-2, https://ubuntu.com/security/notices/USN-4118-1, https://ubuntu.com/security/notices/USN-4351-1, https://www.cve.org/CVERecord?id=CVE-2018-5383
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
