CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)

Posted by Elman Shahbazov on Aug 14

Hello,

I would like to request a CVE ID for an Out-of-Bounds Read vulnerability
(CWE-125) that was recently fixed in the official BlueZ Bluetooth stack.

Vulnerability Type: CWE-125 (Out-of-bounds Read)
Component: profiles/audio/avrcp.c (AVRCP GetFolderItems parsing)
Impact: A remote Bluetooth device acting as an AVRCP controller can send
a specially crafted response with an inflated name length field but a short
packet size, causing...

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论