漏洞信息详情
Bluetooth 加密问题漏洞
漏洞简介
Bluetooth是一种无线技术标准,它能够实现固定设备、移动设备和楼宇个人域网之间的短距离数据交换。
Bluetooth中存在加密问题漏洞,该漏洞源于在Diffie-Hellman密钥交换过程中程序未能充分验证用于生成公钥的椭圆曲线参数。远程攻击者可利用该漏洞获取设备使用的加密密钥,进而拦截,解密,伪造和注入设备消息。以下系统受到影响:macOS 10.13之前版本;macOS High Sierra 11.4之前版本;iOS 11.4之前版本;Android 2018-06-05补丁之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update
参考网址
来源:BID
链接:https://www.securityfocus.com/bid/104879
来源:BID
链接:http://www.securityfocus.com/bid/104879
来源:MISC
链接:http://www.cs.technion.ac.il/~biham/BT/
来源:SECTRACK
链接:http://www.securitytracker.com/id/1041432
来源:UBUNTU
链接:https://usn.ubuntu.com/4094-1/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2169
来源:UBUNTU
链接:https://usn.ubuntu.com/4095-1/
来源:CONFIRM
链接:https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update
来源:UBUNTU
链接:https://usn.ubuntu.com/4095-2/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/04/msg00005.html
来源:UBUNTU
链接:https://usn.ubuntu.com/4118-1/
来源:CERT-VN
链接:https://www.kb.cert.org/vuls/id/304725
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:2169
来源:lists.debian.org
链接:https://lists.debian.org/debian-lts-announce/2019/04/msg00005.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190466-1/
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190422-1/
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/4095-2/
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/4095-1/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2932/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75986
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Bluetooth-Firmware-information-disclosure-via-Weak-Elliptic-Curve-Parameters-28536
来源:support.lenovo.com
链接:https://support.lenovo.com/us/en/product_security/LEN-22233
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157598/Ubuntu-Security-Notice-USN-4351-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75750
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78314
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153946/Red-Hat-Security-Advisory-2019-2169-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1612/
受影响实体
- Google Android:6.0<!--2000-1-1-->
- Google Android:6.0.1<!--2000-1-1-->
- Google Android:7.0<!--2000-1-1-->
- Google Android:7.1.1<!--2000-1-1-->
- Google Android:7.1.2<!--2000-1-1-->
补丁
- Bluetooth 安全漏洞的修复措施<!--2018-7-26-->
还没有评论,来说两句吧...