Oval Definition:oval:com.ubuntu.disco:def:201995060000000
Revision Date:2019-08-14Version:1
Title:CVE-2019-9506 on Ubuntu 19.04 (disco) - medium.
Description:The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing. Daniele Antonioli, Nils Ole Tippenhauer, and Kasper B. Rasmussen discovered that the Bluetooth protocol BR/EDR specification did not properly require sufficiently strong encryption key lengths. A physically proximate attacker could use this to expose sensitive information.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-9506
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND Package Information
  • linux package in disco was vulnerable but has been fixed (note: '5.0.0-31.33').
  • OR linux-aws package in disco was vulnerable but has been fixed (note: '5.0.0-1018.20').
  • OR linux-gcp package in disco was vulnerable but has been fixed (note: '5.0.0-1020.20').
  • OR linux-meta package in disco was vulnerable but has been fixed (note: '5.0.0-31.33').
  • OR linux-meta-aws package in disco was vulnerable but has been fixed (note: '5.0.0-1018.20').
  • OR linux-meta-gcp package in disco was vulnerable but has been fixed (note: '5.0.0-1020.20').
  • OR linux-meta-oem package in disco is affected. An update containing the fix has been completed and is pending publication (note: '4.15.0-1056.65').
  • OR linux-meta-oem-osp1 package in disco is affected and needs fixing.
  • OR linux-meta-oracle package in disco was vulnerable but has been fixed (note: '5.0.0-1004.8').
  • OR linux-meta-raspi2 package in disco was vulnerable but has been fixed (note: '5.0.0-1019.19').
  • OR linux-oem package in disco is affected. An update containing the fix has been completed and is pending publication (note: '4.15.0-1056.65').
  • OR linux-oem-osp1 package in disco is affected and needs fixing.
  • OR linux-oracle package in disco was vulnerable but has been fixed (note: '5.0.0-1004.8').
  • OR linux-raspi2 package in disco was vulnerable but has been fixed (note: '5.0.0-1019.19').
  • OR linux-signed package in disco was vulnerable but has been fixed (note: '5.0.0-31.33').
  • OR linux-signed-gcp package in disco was vulnerable but has been fixed (note: '5.0.0-1020.20').
  • OR linux-signed-oem package in disco is affected. An update containing the fix has been completed and is pending publication (note: '4.15.0-1056.65').
  • OR linux-signed-oem-osp1 package in disco is affected and needs fixing.
  • OR linux-signed-oracle package in disco was vulnerable but has been fixed (note: '5.0.0-1004.8').
  • OR linux-snapdragon package in disco was vulnerable but has been fixed (note: '5.0.0-1023.24').
  • BACK