CVE-2016-9797: Buffer Overflow
Published Dec 3, 2016
·Updated
In BlueZ 5.42, a buffer over-read was observed in "l2capdump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
Affected Software
1 affected component
bluez bluez=5.42
Event History
Dec 3, 2016
CVE Published
via MITRE·06:28 AM
Data Sourced
via MITRE·06:28 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9797?
CVE-2016-9797 is classified as a moderate severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2016-9797?
To fix CVE-2016-9797, update BlueZ to version 5.43 or later.
3
Which software is affected by CVE-2016-9797?
CVE-2016-9797 affects BlueZ version 5.42.
4
What type of vulnerability is CVE-2016-9797?
CVE-2016-9797 is a buffer over-read vulnerability.
5
What can be exploited in CVE-2016-9797?
CVE-2016-9797 can be exploited by processing a corrupted dump file, leading to a crash of the hcidump utility.