CVE-2017-1000250
published 2017-09-12CVE-2017-1000250: All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain…
PriorityP432medium6.5CVSS 3.0
AVAACLPRNUINSUCHINAN
EPSS
7.77%
94.0th percentile
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | <= 5.46 | — |
| bluez | bluez | >= 0 < 5.46-1 | 5.46-1 |
| bluez | bluez | >= 0 < 5.46-1 | 5.46-1 |
| bluez | bluez | >= 0 < 5.46-1 | 5.46-1 |
| bluez | bluez | >= 0 < 5.46-1 | 5.46-1 |
| bluez | bluez | >= 0 < 4.101-0ubuntu13.3 | 4.101-0ubuntu13.3 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.1 | 5.37-0ubuntu5.1 |
| debian | bluez | < bluez 5.46-1 (bookworm) | bluez 5.46-1 (bookworm) |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
BlueZ vulnerability
vendor_ubuntu·2017-09-12·CVSS 6.5
CVE-2017-1000250 [MEDIUM] BlueZ vulnerability
Title: BlueZ vulnerability
Summary: BlueZ could be made to expose sensitive information over bluetooth.
It was discovered that an information disclosure vulnerability existed
in the Service Discovery Protocol (SDP) implementation in BlueZ. A
physically proximate unauthenticated attacker could use this to
disclose sensitive information. (CVE-2017-1000250)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bluez: Out-of-bounds heap read in service_search_attr_req function
vendor_redhat·2017-09-12·CVSS 6.5
CVE-2017-1000250 [MEDIUM] CWE-125 bluez: Out-of-bounds heap read in service_search_attr_req function
bluez: Out-of-bounds heap read in service_search_attr_req function
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
An information-disclosure flaw was found in the bluetoothd implementation of the Service Discovery Protocol (SDP). A specially crafted Bluetooth device could, without prior pairing or user interaction, retrieve portions of the bluetoothd process memory, including potentially sensitive information such as Bluetooth encryption keys.
Package: bluez-utils (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-1000250: bluez - All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an in...
vendor_debian·2017·CVSS 6.5
CVE-2017-1000250 [MEDIUM] CVE-2017-1000250: bluez - All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an in...
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Scope: local
bookworm: resolved (fixed in 5.46-1)
bullseye: resolved (fixed in 5.46-1)
forky: resolved (fixed in 5.46-1)
sid: resolved (fixed in 5.46-1)
trixie: resolved (fixed in 5.46-1)
GHSA
GHSA-6fxm-r64m-667w: All versions of the SDP server in BlueZ 5
ghsa_unreviewed·2022-05-14
CVE-2017-1000250 [MEDIUM] CWE-200 GHSA-6fxm-r64m-667w: All versions of the SDP server in BlueZ 5
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
OSV
bluez vulnerability
osv·2017-09-12·CVSS 6.5
CVE-2017-1000250 [MEDIUM] bluez vulnerability
bluez vulnerability
It was discovered that an information disclosure vulnerability existed
in the Service Discovery Protocol (SDP) implementation in BlueZ. A
physically proximate unauthenticated attacker could use this to
disclose sensitive information. (CVE-2017-1000250)
OSV
CVE-2017-1000250: All versions of the SDP server in BlueZ 5
osv·2017-09-12·CVSS 6.5
CVE-2017-1000250 [MEDIUM] CVE-2017-1000250: All versions of the SDP server in BlueZ 5
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function [fedora-all]
bugzilla·2017-09-12·CVSS 6.5
CVE-2017-1000250 [MEDIUM] CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function [fedora-all]
CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function
bugzilla·2017-09-07·CVSS 6.5
CVE-2017-1000250 [MEDIUM] CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function
CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function
Information disclosure vulnerability due to out-of-bounds heap read in service_search_attr_req function when processing of incoming requests in the SDP server was found. Unauthenticated attacker can exploit this vulnerability to read potentially sensitive data from heap of the bluetoothd process.
Vulnerable code:
...
} else {
/* continuation State exists -> get from cache */
sdp_buf_t *pCache = sdp_get_cached_rsp(cstate);
if (pCache) {
uint16_t sent = MIN(max, pCache->data_size -
cstate->cStateValue.maxBytesSent);
pResponse = pCache->data;
memcpy(buf->data,
pResponse + cstate->cStateValue.maxBytesSent,
sent);
buf->data_size += sent;
cstate->cStateValue.maxBytesSent += sent;
if (cstate->cStateValue.maxByt
Tenable
Protecting Your Bluetooth Devices from BlueBorne
blogs_tenable·2017-09-15·CVSS 6.5
[MEDIUM] Protecting Your Bluetooth Devices from BlueBorne
Blog /
Subscribe
# Protecting Your Bluetooth Devices from BlueBorne
David Schwalenberg
September 15, 2017
1 Min Read
A new attack vector, codenamed BlueBorne, can potentially affect all devices with Bluetooth capabilities – ordinary computers, mobile phones, and IoT devices – literally billions of devices in the world today. Hackers can use this attack vector to leverage Bluetooth connections to completely take over targeted devices.
BlueBorne spreads through the air, allowing it to bypass all security measures and potentially infect even “air-gapped” networks. The attack does not require the attacker’s device and the targeted device to be paired; in fact, the targeted device does not even need to be set on discoverable mode. The BlueBorne attack vector requires no user interaction,
Tenable
Protecting Your Bluetooth Devices from BlueBorne
blogs_tenable·2017-09-15
Protecting Your Bluetooth Devices from BlueBorne
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
BlueBorne May Affect Billions of Bluetooth Devices
blogs_fortinet·2017-09-14·CVSS 8.8
[HIGH] BlueBorne May Affect Billions of Bluetooth Devices
FORTIGUARD LABS THREAT RESEARCH
BlueBorne May Affect Billions of Bluetooth Devices
By Aamir Lakhani | September 14, 2017
Bluetooth is one of the most widely deployed and used connectivity protocols in the world. Everything from electronic devices to smartphones uses it, as do a growing number of IoT devices. Now, a new Bluetooth exploit, known as BlueBorne, exploits a number of Bluetooth vulnerabilities, making literally billions of devices potentially vulnerable to attack.
BlueBorne is a hybrid Trojan-Worm malware that spreads via Bluetooth. Because it includes worm-like properties, any infected system is also a potential carrier, and will actively search for vulnerable hosts. Unfortunately, vulnerable hosts can include any Bluetooth-enabled device, including Android, iOS, Mac OSX, a
http://nvidia.custhelp.com/app/answers/detail/a_id/4561http://www.debian.org/security/2017/dsa-3972http://www.securityfocus.com/bid/100814https://access.redhat.com/errata/RHSA-2017:2685https://access.redhat.com/security/vulnerabilities/bluebornehttps://www.armis.com/bluebornehttps://www.kb.cert.org/vuls/id/240311https://www.synology.com/support/security/Synology_SA_17_52_BlueBornehttps://access.redhat.com/security/cve/CVE-2017-1000250http://nvidia.custhelp.com/app/answers/detail/a_id/4561http://www.debian.org/security/2017/dsa-3972http://www.securityfocus.com/bid/100814https://access.redhat.com/errata/RHSA-2017:2685https://access.redhat.com/security/vulnerabilities/bluebornehttps://www.armis.com/bluebornehttps://www.kb.cert.org/vuls/id/240311https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne
2017-09-12
Published