CVE-2005-3534
Last modified
CVE-2005-3534 is a vulnerability of currently unknown severity. Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.. EPSS estimates a 5.99% chance of exploitation in the next 30 days.
Description
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wouter Verhelst | Nbd | <= 2.7.5 |
| Wouter Verhelst | Nbd | 2.8.0 |
| Wouter Verhelst | Nbd | 2.8.2 |
References
- http://secunia.com/advisories/18135Vendor Advisory
- http://secunia.com/advisories/18171Patch, Vendor Advisory
- http://secunia.com/advisories/18209Patch, Vendor Advisory
- http://secunia.com/advisories/18315Patch, Vendor Advisory
- http://secunia.com/advisories/18503Vendor Advisory
- http://www.debian.org/security/2005/dsa-924Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlPatch, Vendor Advisory
- http://secunia.com/advisories/18135Vendor Advisory
- http://secunia.com/advisories/18171Patch, Vendor Advisory
- http://secunia.com/advisories/18209Patch, Vendor Advisory
- http://secunia.com/advisories/18315Patch, Vendor Advisory
- http://secunia.com/advisories/18503Vendor Advisory
- http://www.debian.org/security/2005/dsa-924Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3534?
How severe is CVE-2005-3534?
How do I fix CVE-2005-3534?
Are you affected by CVE-2005-3534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
