CVE-2011-0530: Buffer Overflow
Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
Other sources
Originally, CVE-2005-3534: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3534
has been assigned to NBD and addressed in nbd-v2.8.3 version: [2] http://sourceforge.net/project/shownotes.php?releaseid=380202&groupid=13229
via changeset: [3] https://github.com/yoe/nbd/commit/4ed24fe0d64c7cc9963c57b52cad1555ad7c6b60
But nbd-v2.9.0: [4] http://sourceforge.net/projects/nbd/files/nbd/2.9.0/
contains the issue again. This flaw was fixed second time via upstream changeset: [5] https://github.com/yoe/nbd/commit/3ef52043861ab16352d49af89e048ba6339d6df8
References: [6] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611187
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0530?
CVE-2011-0530 has a high severity due to the potential for remote code execution.
How do I fix CVE-2011-0530?
To fix CVE-2011-0530, you should upgrade to Network Block Device version 2.9.20 or later.
What causes the vulnerability CVE-2011-0530?
CVE-2011-0530 is caused by a buffer overflow in the mainloop function of the nbd-server implementation.
Which versions are affected by CVE-2011-0530?
CVE-2011-0530 affects nbd versions prior to 2.9.20, including versions from 2.9.0 to 2.9.19.
Can CVE-2011-0530 lead to data breaches?
Yes, CVE-2011-0530 can potentially lead to data breaches by allowing remote attackers to execute arbitrary code.