CVE-2021-33833: Buffer Overflow
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2021-33833?
CVE-2021-33833 is a stack-based buffer overflow in ConnMan (Connection Manager) 1.30 through 1.39, specifically in the uncompress function in dnsproxy.c via NAME, RDATA, or RDLENGTH.
How severe is CVE-2021-33833?
CVE-2021-33833 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2021-33833?
ConnMan versions 1.30 through 1.39 are affected by CVE-2021-33833.
How can I fix CVE-2021-33833?
To fix CVE-2021-33833, update to ConnMan version 1.35-6ubuntu0.1~ for Ubuntu Bionic, 1.36-2ubuntu0.1 for Ubuntu Focal, or apply the appropriate remedy provided by Debian if running a Debian-based system.
Where can I find more information about CVE-2021-33833?
You can find more information about CVE-2021-33833 at the following references: [https://lore.kernel.org/connman/](https://lore.kernel.org/connman/), [http://www.openwall.com/lists/oss-security/2021/06/09/1](http://www.openwall.com/lists/oss-security/2021/06/09/1), [https://security.gentoo.org/glsa/202107-29](https://security.gentoo.org/glsa/202107-29).