All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1103-1 | bluez security update |
Debian DSA |
DSA-3972-1 | bluez security update |
Ubuntu USN |
USN-3413-1 | BlueZ vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T22:00:39.877Z
Reserved: 2017-09-12T00:00:00
Link: CVE-2017-1000250
No data.
Status : Deferred
Published: 2017-09-12T17:29:00.197
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000250
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN