Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2374

Опубликовано: 07 июл. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

feisty

DNE

gutsy

DNE

hardy

DNE

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

Показывать по

EPSS

Процентиль: 90%
0.06044
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
около 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
nvd
почти 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
debian
почти 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.3 ...

CVSS3: 9.8
github
около 3 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

oracle-oval
почти 17 лет назад

ELSA-2008-0581: bluez-libs and bluez-utils security update (MODERATE)

EPSS

Процентиль: 90%
0.06044
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3