RHSA-2017:2685-01 -- Redhat bluezID: oval:org.secpod.oval:def:502134 | Date: (C)2017-09-22 (M)2023-12-20 |
Class: PATCH | Family: unix |
The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts , and pcmcia configuration files. Security Fix: * An information-disclosure flaw was found in the bluetoothd implementation of the Service Discovery Protocol . A specially crafted Bluetooth device could, without prior pairing or user interaction, retrieve portions of the bluetoothd process memory, including potentially sensitive information such as Bluetooth encryption keys. Red Hat would like to thank Armis Labs for reporting this issue.
Platform: |
Red Hat Enterprise Linux 7 |
Red Hat Enterprise Linux 6 |