Bug 1104301 - (CVE-2018-5383) VUL-0: CVE-2018-5383: kernel-firmware: Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
(CVE-2018-5383)
VUL-0: CVE-2018-5383: kernel-firmware: Bluetooth implementations may not suff...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/212445/
CVSSv3:RedHat:CVE-2018-5383:7.1:(AV:A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-08-09 07:08 UTC by Marcus Meissner
Modified: 2019-07-11 06:38 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-08-09 07:08:59 UTC
Bluetooth firmware or operating system software drivers in macOS versions before
10.13, High Sierra and iOS versions before 11.4, and Android versions before the
2018-06-05 patch may not sufficiently validate elliptic curve parameters used to
generate public keys during a Diffie-Hellman key exchange, which may allow a
remote attacker to obtain the encryption key used by the device.

References:
https://www.kb.cert.org/vuls/id/304725
https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-update
http://www.cs.technion.ac.il/~biham/BT/
Comment 8 Swamp Workflow Management 2019-02-18 20:09:38 UTC
SUSE-SU-2019:0422-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1104301
CVE References: CVE-2018-5383
Sources used:
SUSE Linux Enterprise Server 12-LTSS (src):    kernel-firmware-20140807git-5.11.1
Comment 9 Swamp Workflow Management 2019-02-19 14:10:57 UTC
SUSE-SU-2019:0427-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1104301
CVE References: CVE-2018-5383
Sources used:
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    kernel-firmware-20160516git-10.16.1
Comment 10 Swamp Workflow Management 2019-02-22 14:25:39 UTC
SUSE-SU-2019:0466-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1104301
CVE References: CVE-2018-5383
Sources used:
SUSE OpenStack Cloud 7 (src):    kernel-firmware-20170530-21.28.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    kernel-firmware-20170530-21.28.1
SUSE Linux Enterprise Server 12-SP3 (src):    kernel-firmware-20170530-21.28.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    kernel-firmware-20170530-21.28.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    kernel-firmware-20170530-21.28.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    kernel-firmware-20170530-21.28.1
SUSE Enterprise Storage 4 (src):    kernel-firmware-20170530-21.28.1
SUSE CaaS Platform ALL (src):    kernel-firmware-20170530-21.28.1
SUSE CaaS Platform 3.0 (src):    kernel-firmware-20170530-21.28.1
Comment 11 Swamp Workflow Management 2019-03-01 17:09:21 UTC
openSUSE-SU-2019:0275-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1104301
CVE References: CVE-2018-5383
Sources used:
openSUSE Leap 42.3 (src):    kernel-firmware-20170530-26.1
Comment 12 Swamp Workflow Management 2019-04-27 22:11:00 UTC
SUSE-SU-2019:0427-2: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1104301
CVE References: CVE-2018-5383
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    kernel-firmware-20160516git-10.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Marcus Meissner 2019-07-11 06:07:00 UTC
done