bluez-5.50-3.el8

エラータID: AXSA:2020-298:02

Release date: 
Tuesday, September 8, 2020 - 04:38
Subject: 
bluez-5.50-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Low
Description: 

The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, l2ping, start scripts (Asianux), and pcmcia configuration files.

Security Fix(es):

* bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices (CVE-2018-10910)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.2 Release Notes linked from the References section.

CVE-2018-10910
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. bluez-5.50-3.el8.src.rpm
    MD5: 6bb06ca717e173e5ab7a8de7fd1b6ecd
    SHA-256: c8a9088e1f082bc5dbf9403e191e40b2c3e022ab7ff03e4593d1d274f3c86366
    Size: 1.72 MB

Asianux Server 8 for x86_64
  1. bluez-5.50-3.el8.x86_64.rpm
    MD5: 148a677d2eb47ef8426c3a4705e70274
    SHA-256: cf83b7007b945409ba1f6850c2d2909faa9a81fa3c830b05cc41a6b41d9d26e0
    Size: 1.24 MB
  2. bluez-cups-5.50-3.el8.x86_64.rpm
    MD5: cbcbf49ec977ea21bfc60f230fd1e966
    SHA-256: 3111cdbce895e7b2b854b3251fba8a46ed535b1b3284737d95cdaa5f4f5d58b2
    Size: 92.41 kB
  3. bluez-hid2hci-5.50-3.el8.x86_64.rpm
    MD5: 7a1022453b8b42ceec13c862eab2fc44
    SHA-256: 507c19f179d42d88ac1f19f77aca15e20f8cf10cb76ccb43e52c9d4b357b4295
    Size: 38.54 kB
  4. bluez-libs-5.50-3.el8.x86_64.rpm
    MD5: 89384a0dd7d579e93115e20272a42bce
    SHA-256: fcd4f382f586e4d040bedc45ab1c6940a270caf71d32eaa74e0b12f5f8b51def
    Size: 90.64 kB
  5. bluez-obexd-5.50-3.el8.x86_64.rpm
    MD5: ad14e23dc4626c345ff1b55e039b0e33
    SHA-256: 8e50e05e0457163e43063411e3db30cfd45ae4c5c24decea8205e648d8eeddf6
    Size: 209.14 kB
  6. bluez-libs-5.50-3.el8.i686.rpm
    MD5: 48e3766fc19c65328aa4deca76c9d957
    SHA-256: 3fbe5f9557fdbc7207bb96852749fa47d8d81bd6d0733734fe876d80c7d896c5
    Size: 92.89 kB