CVE-2005-3534
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.99% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- wouter verhelst/nbd
- Source
- security@debian.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=116314
- http://secunia.com/advisories/18135Vendor Advisory
- http://secunia.com/advisories/18171Patch, Vendor Advisory
- http://secunia.com/advisories/18209Patch, Vendor Advisory
- http://secunia.com/advisories/18315Patch, Vendor Advisory
- http://secunia.com/advisories/18503Vendor Advisory
- http://secunia.com/advisories/43353
- http://secunia.com/advisories/43610
- http://sourceforge.net/mailarchive/forum.php?thread_id=9201144&forum_id=40388
- http://sourceforge.net/project/shownotes.php?release_id=380202&group_id=13229Patch
- http://sourceforge.net/project/shownotes.php?release_id=380210&group_id=13229Patch
- http://www.debian.org/security/2005/dsa-924Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlPatch, Vendor Advisory
- http://www.osvdb.org/21848Patch
- http://www.securityfocus.com/bid/16029Patch
- https://usn.ubuntu.com/237-1/
- http://bugs.gentoo.org/show_bug.cgi?id=116314
- http://secunia.com/advisories/18135Vendor Advisory
- http://secunia.com/advisories/18171Patch, Vendor Advisory
- http://secunia.com/advisories/18209Patch, Vendor Advisory
- http://secunia.com/advisories/18315Patch, Vendor Advisory
- http://secunia.com/advisories/18503Vendor Advisory
- http://secunia.com/advisories/43353
- http://secunia.com/advisories/43610
- http://sourceforge.net/mailarchive/forum.php?thread_id=9201144&forum_id=40388
- http://sourceforge.net/project/shownotes.php?release_id=380202&group_id=13229Patch
- http://sourceforge.net/project/shownotes.php?release_id=380210&group_id=13229Patch
- http://www.debian.org/security/2005/dsa-924Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlPatch, Vendor Advisory
- http://www.osvdb.org/21848Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.