Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1747-1 | firmware-nonfree security update |
EUVD |
EUVD-2018-17154 | Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device. |
Ubuntu USN |
USN-4094-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4095-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4095-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-4118-1 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-4351-1 | Linux firmware vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-09-16T20:36:44.114Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5383
No data.
Status : Modified
Published: 2018-08-07T21:29:00.287
Modified: 2024-11-21T04:08:42.640
Link: CVE-2018-5383
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN