﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
9765	bluez-5.47	ken@…	ken@…	"Among other changes, this release fixes CVE-2017-1000250 :
	
""All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.""

Publicized as ""BlueBorne"", [https://arstechnica.com/information-technology/2017/09/bluetooth-bugs-open-billions-of-devices-to-attacks-no-clicking-required] - /me is glad he has no bluetooth devices.

Fedora had patched 5.46 with a slightly different fix, but they have now moved to 5.47 and dropped that patch.

Full set of announced changes:

ver 5.47:
        Fix issue with handling AcquireNotify registration.

        Fix issue with handling support for reconnection interval.

        Fix issue with handling A2DP transport and accepting streams.

        Fix issue with fallback from BR/EDR to LE bearer handling.

        Add support for appearance and local name advertising data.

        Add support for retrieving the supported discovery filters.

        Add support for decoding Bluetooth 5.0 commands and events.

        Add support for decoding Bluetooth Mesh advertising bearer.

        Add support for Bluetooth Mesh control application.

"	defect	closed	high	8.2	BOOK	SVN	medium	fixed		
