CVE-2005-3534: Buffer Overflow
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3534?
CVE-2005-3534 has a critical severity level due to the potential for remote code execution.
How do I fix CVE-2005-3534?
To fix CVE-2005-3534, upgrade to a patched version of the NBD server later than 2.8.2.
Which versions of NBD are affected by CVE-2005-3534?
CVE-2005-3534 affects NBD versions 2.7.5 and earlier, as well as versions 2.8.0 through 2.8.2.
What type of attack is associated with CVE-2005-3534?
CVE-2005-3534 is associated with a buffer overflow attack that allows remote attackers to execute arbitrary code.
Can CVE-2005-3534 be exploited remotely?
Yes, CVE-2005-3534 can be exploited remotely due to its nature of allowing arbitrary code execution through crafted large requests.