CVE-2018-10910
published 2019-01-28CVE-2018-10910: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead…
PriorityP411low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.46%
37.0th percentile
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | < 5.51 | 5.51 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| bluez | bluez | >= 0 < 5.54-1 | 5.54-1 |
| canonical | ubuntu_linux | — | — |
| debian | bluez | < bluez 5.54-1 (bookworm) | bluez 5.54-1 (bookworm) |
| the_bluez_project | bluez | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian4.5LOW
vendor_redhat4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Bluetooth vulnerability
vendor_ubuntu·2019-01-14
CVE-2018-10910 GNOME Bluetooth vulnerability
Title: GNOME Bluetooth vulnerability
Summary: GNOME Bluetooth could allow unintended access to devices.
Chris Marchesi discovered that BlueZ incorrectly handled disabling
Bluetooth visibility. A remote attacker could possibly pair to devices,
contrary to expectations. This update adds a workaround to GNOME Bluetooth
to fix the issue.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
vendor_redhat·2018-07-20·CVSS 4.5
CVE-2018-10910 [MEDIUM] CWE-863 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication.
Mitigation: Disable Bluetooth.
Package: bluez (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2018-10910: bluez - A bug in Bluez may allow for the Bluetooth Discoverable state being set to on wh...
vendor_debian·2018·CVSS 4.5
CVE-2018-10910 [MEDIUM] CVE-2018-10910: bluez - A bug in Bluez may allow for the Bluetooth Discoverable state being set to on wh...
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
Scope: local
bookworm: resolved (fixed in 5.54-1)
bullseye: resolved (fixed in 5.54-1)
forky: resolved (fixed in 5.54-1)
sid: resolved (fixed in 5.54-1)
trixie: resolved (fixed in 5.54-1)
GHSA
GHSA-62rf-fp64-gxpc: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system
ghsa_unreviewed·2022-05-13
CVE-2018-10910 [LOW] CWE-863 GHSA-62rf-fp64-gxpc: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
OSV
CVE-2018-10910: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system
osv·2019-01-28·CVSS 3.3
CVE-2018-10910 [LOW] CVE-2018-10910: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
bugzilla·2019-06-12·CVSS 5.3
CVE-2019-10909 [MEDIUM] CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
Multiple vulnerabilities were discovered in the Symfony PHP framework
which could lead to cache bypass, authentication bypass, information
disclosure, open redirect, cross-site request forgery, deletion of
arbitrary files, or arbitrary code execution.
References:
https://www.debian.org/security/2019/dsa-4441
https://security-tracker.debian.org/tracker/symfony
Discussion:
Created php-symfony tracking bugs for this issue:
Affects: epel-all [bug 1719512]
Affects: fedora-all [bug 1719511]
Created php-symfony3 tracking bugs for this issue:
Affects: fedora-all [bug 1719513]
Created php-symfony4 tracking bugs for this issue:
Affects: fe
Bugzilla
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices [fedora-all]
bugzilla·2018-07-20·CVSS 4.5
CVE-2018-10910 [MEDIUM] CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices [fedora-all]
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
bugzilla·2018-07-20·CVSS 4.5
CVE-2018-10910 [MEDIUM] CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices
A bug in bluez prevents the disabling of Bluetooth discoverability. In certain situations, this flaw could potentially lead to the unauthorized pairing of Bluetooth devices.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1602985
Discussion:
Upstream workaround in gnome-bluetooth: https://gitlab.gnome.org/GNOME/gnome-bluetooth/commit/6b5086d42ea64d46277f3c93b43984f331d12f89
Note that the actual bug is not in gnome-bluetooth.
RHEL is not affected as RHEL-7 is running Gnome 3.26, which is not impacted.
---
Created bluez tracking bugs for this issue:
Affects: fedora-all [bug 1606371]
---
Acknowledgments:
Name: Chris Marchesi
---
2019-01-28
Published