CVE-2019-8921 Information
Jun 07, 2022
cve
Description
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE it is possible to trick the server into returning more bytes than the buffer actually holds resulting in leaking arbitrary heap data. The root cause can be found in the function service_attr_req of sdpd-request.c. The server does not check whether the CSTATE data is the same in consecutive requests and instead simply trusts that it is the same.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://ssd-disclosure.com/ssd-advisory-linux-bluez-information-leak-and-heap-overflow/ https://security.netapp.com/advisory/ntap-20211203-0002/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: