CVE-2016-9917: Buffer Overflow
Published Dec 8, 2016
·Updated
In BlueZ 5.42, a buffer overflow was observed in "readn" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
Affected Software
1 affected component
bluez bluez=5.42
Event History
Dec 8, 2016
CVE Published
via MITRE·08:08 AM
Data Sourced
via MITRE·08:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9917?
CVE-2016-9917 has been classified as a moderate severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2016-9917?
To fix CVE-2016-9917, upgrade to a patched version of BlueZ beyond 5.42.
3
What software is affected by CVE-2016-9917?
CVE-2016-9917 specifically affects BlueZ version 5.42.
4
What is the impact of CVE-2016-9917?
The impact of CVE-2016-9917 is that it can lead to a buffer overflow causing the hcidump tool to crash.
5
Can CVE-2016-9917 be exploited remotely?
CVE-2016-9917 requires a corrupted dump file to be processed, so it is less likely to be exploited remotely without user interaction.