Canadian Centre for Cyber Security · English · AV18-012Oracle Critical Patch updates195, CVE-2015-3253, CVE-2015-4852, CVE-2015-7501, CVE-2015-7547, CVE-2015-7940, CVE-2016-0635, CVE-2016-0703, CVE-2016-0704, CVE-2016-0800, CVE-2016-1181, CVE-2016-1182, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2518, CVE-2016-2550, CVE-2016-4449, CVE-2016-5385, CVE-2016-5387, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-7055, CVE-2016-7977, CVE-2016-8735, CVE-2016-9878, CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, CVE-2017-0785, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2017-3733, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5461, CVE-2017-5645, CVE-2017-5664, CVE-2017-5715, CVE-2017-9072, CVE-2017-9798, CVE-2017-10068, CVE-2017-10262, CVE-2017-10273, CVE-2017-10282, CVE-2017-10301, CVE-2017-10352, CVE-2017-12617, CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2018-2560, CVE-2018-2561, CVE-2018-2562, CVE-2018-2564, CVE-2018-2565, CVE-2018-2566, CVE-2018-2567, CVE-2018-2568, CVE-2018-2569, CVE-2018-2570, CVE-2018-2571, CVE-2018-2573, CVE-2018-2574, CVE-2018-2575, CVE-2
Official advisory ↗Canadian Centre for Cyber Security · English · AL17-011Bluetooth Critical VulnerabilitiesCCIRC has become aware of multiple critical vulnerabilities in the implementation of the Bluetooth stack in multiple versions of Android, Apple iOS, Microsoft Windows and Linux based products, among others. The vulnerabilities could allow for a malicious threat actor to execute code, intercept wireless communications, abuse device functionality and/or perform man-in-the-middle attacks. While no known active exploitation has been reported, a working proof of concept is available.
Open source reporting describing the vulnerabilities suggests that exploitation does not require the targeted device to be set on discoverable mode or paired to the threat actor's device; furthermore, authorization is not required by the end user nor does it require authentication for the connection to be made.
CCIRC recommends information security teams to monitor for future vendor supplied updates and apply relevant security patches as they become available. Below is a list of the potentially affected products and their relevant versions:
Android
Android phones, tablets, and wearables of all versions are affected by the four following vulnerabilities:
CVE-2017-0781: Android Remote Code Execution Vulnerability
CVE-2017-0782: Android Remote Code Execution Vulnerability
CVE-2017-0783: Android Potential Man in the Middle Attack
CVE-2017-0785: Android Bluetooth Information Leak Vulnerability
Android devices using Bluetooth Low Energy only are not affected.
The vulnerabilities affecting Marshmallow (6.0) and Nougat (7.0) Android devices were addressed in Google's Android Security Bulletin released September 12th, 2017.
Apple
The following vulnerability affecting iPhone, iPad and iPod touch devices with iOS 7 through 9 and Apple TV devices with version 7.2.2 and lower:
CVE-2017-14315: Apple Low Energy Audio Remote Code Execution Vulnerability
The vulnerability affecting Apple devices has been resolved in iOS 10, released in September 2016.
Microsoft
Windows versions 10, 8.1, 7, Server 2016 and Server 2008 are affected by the following vulnerability:
CVE-2017-8628: Microsoft Bluetooth Driver Spoofing Vulnerability
The vulnerability affecting Microsoft devices has been resolved by a security update released September 12, 2017.
Linux
Linux devices running BlueZ 5.46 and earlier are affected by:
CVE-2017-1000250: Linux Bluetooth Information Leak Vulnerability
The vulnerability affecting Red Hat Enterprise Linux 7 and 6 devices has been resolved by a security update released by Red Hat on September 12, 2017.
Linux kernel versions 3.3-rc1 and up to and including 4.13.1 are affected by the following:
CVE-2017-1000251: Linux Remote Code Execution Vulnerability
Red Hat Enterprise Linux 5 is not affected.
The vulnerability affecting Red Hat Enterprise Linux 7, 6 and MRG 2 devices has been resolved by a security update released by Red Hat on September 12, 2017.
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4790BlueBorne 블루투스 공격 관련 보안 업데이트 권고#### BlueBorne 블루투스 공격 관련 보안 업데이트 권고 2017.09.14
2017-09-26 : 임시 조치 방안 추가
##### □ 개요
o Armis Labs에서 Android, iOS, Windows, Linux 운영 체제를 사용하는 모바일, 데스크톱, IoT 기기들의 블루투스 기능과 관련된
취약점을 공개[1]
o 해당 취약점에 영향을 받는 버전 사용자는 업데이트 정보를 참고하여 최신버전으로 업데이트 권고
##### □ 취약점 설명
o 안드로이드 BNEP(Bluetooth Network Encapsulation Protocol, 테더링)에서 발생하는 원격코드실행 취약점(CVE-2017-0781)
o 안드로이드의 BNEP PAN(Personal Area Networking, IP기반 장치간 네트워크 연결) 프로필에서 발생하는
원격코드실행 취약점 (CVE-2017-0782)
o 안드로이드의 블루투스의 PAN 프로필에서 발생하는 Man-in-the-Middle 공격 취약점(CVE-2017-0783)
o 안드로이드 SDP(Service Discovery Protocol, 주변 장치 식별)에서 발생하는 정보노출 취약점(CVE-2017-0785)
o 윈도우의 블루투스 드라이버에서 발생하는 스푸핑 취약점(CVE-2017-8628)
o 리눅스 블루투스 스택(BlueZ)에서 발생하는 정보노출 취약점 (CVE-2017-1000250)
o 리눅스 커널 원격코드실행 취약점(CVE-2017-1000251)
o 애플의 Low Energy 오디오 프로토콜에서 발생하는 원격코드실행 취약점 (CVE-2017-14315)
##### □ 해결 방안
o 보안 업데이트가 발표되지 않은 기기의 경우 업데이트 적용을 하기 전까지 Bluetooth 기능을 off 하는 것을 권고
o 블루투스 기기에 off 기능이 없는 경우 사용 자제할 것을 권고
o Mobile
- SAMSUNG [2]
- LG [3]
- Android [4]
- Apple
※ iOS 9.3.5 이하 버전 및 7.2.2 이하 버전의 AppleTV 장치가있는 모든 iPhone, iPad, iPod touch 장치가 해당 취약점에
영향을 받지만 iOS 10에서 패치 완료
o Desktop
- MS [5]
o Linux
- Red Hat/CentOS [6][7]
- Ubuntu [8]
- Fedora [9]
- S
Official advisory ↗