Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10910

Опубликовано: 28 янв. 2019
Источник: debian
EPSS Низкий

Описание

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bluezfixed5.54-1package
bluezignoredbusterpackage
bluezignoredstretchpackage
bluezno-dsajessiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1606203

  • https://bugzilla.redhat.com/show_bug.cgi?id=1602985

  • Bug in src:bluez itself and would need fixing there, but it is workaroundable in

  • gnome-bluetooth: https://gitlab.gnome.org/GNOME/gnome-bluetooth/commit/6b5086d42ea64d46277f3c93b43984f331d12f89

  • workaround in gnome-bluetooth landed in 3.28.2, BlueZ fixed in 5.51

EPSS

Процентиль: 18%
0.00057
Низкий

Связанные уязвимости

CVSS3: 4.5
ubuntu
около 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS3: 4.5
redhat
больше 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS3: 4.5
nvd
около 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS3: 3.3
github
больше 3 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

oracle-oval
почти 6 лет назад

ELSA-2020-1912: bluez security update (LOW)

EPSS

Процентиль: 18%
0.00057
Низкий