CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)
Posted by Elman Shahbazov on Aug 14
Hello,
I would like to request a CVE ID for an Out-of-Bounds Read vulnerability
(CWE-125) that was recently fixed in the official BlueZ Bluetooth stack.
Vulnerability Type: CWE-125 (Out-of-bounds Read)
Component: profiles/audio/avrcp.c (AVRCP GetFolderItems parsing)
Impact: A remote Bluetooth device acting as an AVRCP controller can send
a specially crafted response with an inflated name length field but a short
packet size, causing...
评论
?
参与讨论