CVE-2016-9918: High severity bluez vulnerability
Published Dec 8, 2016
·Updated
In BlueZ 5.42, an out-of-bounds read was identified in "packethexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
Affected Software
1 affected component
Bluez Project Bluez=5.42
Event History
Dec 8, 2016
CVE Published
via MITRE·08:08 AM
Data Sourced
via MITRE·08:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9918?
CVE-2016-9918 has been classified as a medium severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2016-9918?
To fix CVE-2016-9918, you should apply the latest security updates for BlueZ that address this vulnerability.
3
What causes CVE-2016-9918?
CVE-2016-9918 is caused by an out-of-bounds read in the 'packet_hexdump' function when processing a corrupted dump file.
4
Which software versions are affected by CVE-2016-9918?
CVE-2016-9918 affects BlueZ version 5.42.
5
What is the impact of exploiting CVE-2016-9918?
Exploiting CVE-2016-9918 can result in a crash of the btmon tool, impacting its functionality.