CVE-2016-7837: Buffer Overflow
Published Jun 9, 2017
·Updated
Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parseline function used in some userland utilities.
Affected Software
2 affected componentsFixes available
BlueZ BlueZ<=5.41
debian/bluez
5.55-3.1+deb11u15.55-3.1+deb11u25.66-1+deb12u25.66-1+deb12u15.82-1.15.84-15.85-3
Remediation
Event History
Jun 9, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:21 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·06:34 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2016-7837.
2
What is the severity rating of CVE-2016-7837?
The severity rating of CVE-2016-7837 is high with a score of 7.8.
3
What is the affected software?
The affected software is BlueZ versions 5.41 and earlier.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing arbitrary code via the parse_line function used in some BlueZ userland utilities.
5
How can I mitigate this vulnerability?
To mitigate this vulnerability, update BlueZ to version 4.101-0ubuntu13.3 (for Ubuntu 14.04 Trusty), version 5.43-1 (for Ubuntu upstream), version 5.37-0ubuntu5.3 (for Ubuntu 16.04 Xenial), or a later version.