Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nbd | Jul 30, 2024 | Feb 22, 2011 |
| Gentoo Linux | — | Upgrade sys-block/nbd. | Oct 30, 2017 | Feb 22, 2011 |
| Suse | — | Upgrade nbd-docUpgrade sap-aio-releaseUpgrade nbd | Feb 17, 2015 | Feb 22, 2011 |
| Ubuntu | — | Upgrade nbd-server | Nov 8, 2024 | Feb 22, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub