CVE-2016-9803
Summary
| CVE | CVE-2016-9803 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-03 06:59:00 UTC |
| Updated | 2016-12-07 19:28:00 UTC |
| Description | In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed. |
Risk And Classification
Problem Types: CWE-119 | CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| multiple buffer overflows and out-of-bound reads — Linux Bluetooth | MISC | www.spinics.net | Exploit, Third Party Advisory |
| BlueZ Buffer Overflow and Denial of Service Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 752714 SUSE Enterprise Linux Security Update for bluez (SUSE-SU-2022:3718-1)