Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2374

Опубликовано: 07 июл. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 7.5
CVSS3: 9.8

Описание

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

feisty

DNE

gutsy

DNE

hardy

DNE

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

maverick

DNE

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
nvd
больше 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
debian
больше 17 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.3 ...

CVSS3: 9.8
github
почти 4 года назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

oracle-oval
больше 17 лет назад

ELSA-2008-0581: bluez-libs and bluez-utils security update (MODERATE)

7.5 High

CVSS2

9.8 Critical

CVSS3