CVE-2021-26675: Buffer Overflow
Published Feb 9, 2021
·Updated
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
Affected Software
8 affected componentsFixes available
ubuntu/connman<1.36-2.1
1.36-2.1
ubuntu/connman<1.35-6ubuntu0.1~
1.35-6ubuntu0.1~
ubuntu/connman<1.36-2ubuntu0.1
1.36-2ubuntu0.1
debian/connman
1.36-2.1~deb10u21.36-2.1~deb10u51.36-2.2+deb11u21.41-31.42-5
Intel Connman<1.39
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Leap=15.2
Remediation
Event History
Feb 9, 2021
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26675.
2
What is the severity of CVE-2021-26675?
The severity of CVE-2021-26675 is high, with a severity value of 8.8.
3
What is the affected software?
The affected software is ConnMan versions 1.36-2.1 and earlier.
4
How can network adjacent attackers exploit CVE-2021-26675?
Network adjacent attackers can exploit CVE-2021-26675 to execute code by triggering a stack-based buffer overflow in dnsproxy.
5
Where can I find more information about CVE-2021-26675?
You can find more information about CVE-2021-26675 at the following references: [link-1], [link-2], [link-3].