CVE-2021-26675

A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.

Summary:

A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.

Reference Links(if available):

  • https://www.openwall.com/lists/oss-security/2021/02/08/2
  • https://bugzilla.suse.com/show_bug.cgi?id=1181751
  • https://git.kernel.org/pub/scm/network/connman/connman.git/tree/ChangeLog
  • https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?id=e4079a20f617a4b076af503f6e4e8b0304c9f2cb
  • https://lists.debian.org/debian-lts-announce/2021/02/msg00013.html
  • CVSS Score (if available)

    v2: / MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P

    v3: / HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)