Permissions, Privileges, and Access Controls in BlueZ - CVE-2018-10910

 

Permissions, Privileges, and Access Controls in BlueZ - CVE-2018-10910

Published: December 2, 2019


Vulnerability identifier: #VU23113
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10910
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists in BlueZ due to an error that may allow an attacker to turn on the Bluetooth Discoverable state, when no Bluetooth agent is registered with the system. A remote attacker with physical proximity to the device can remotely turn on Bluetooth agent and access the device without authorization in some cases.


Affected software

BlueZ
bluez (Red Hat package)
bluez
bluez-cups
bluez-debuginfo
bluez-debugsource
bluez-devel
bluez-help
bluez-libs
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
openEuler

How to mitigate CVE-2018-10910

Install updates from vendor's website.

BlueZ - update to 5.51
bluez (Red Hat package) - addressed in versions 5.44-6.el7, 5.50-3.el8
bluez - update to 5.50-8
bluez-cups - update to 5.50-8
bluez-debuginfo - update to 5.50-8
bluez-debugsource - update to 5.50-8
bluez-devel - update to 5.50-8
bluez-help - update to 5.50-8
bluez-libs - update to 5.50-8

External References

Related Security Bulletins