First published: Sat Dec 03 2016(Updated: )
In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlueZ | =5.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9799 has been classified as a high severity vulnerability due to the potential for a buffer overflow leading to crashes.
To mitigate CVE-2016-9799, it is recommended to upgrade to a version of BlueZ higher than 5.42 where the vulnerability has been addressed.
CVE-2016-9799 is caused by a buffer overflow in the 'pklg_read_hci' function when processing a corrupted dump file.
BlueZ version 5.42 is the only version affected by CVE-2016-9799.
Exploiting CVE-2016-9799 can lead to the crash of the btmon tool when it processes a maliciously crafted dump file.