PT-2019-20122 · Gattlib · Gattlib

Publicado

2019-01-21

·

Atualizado

2019-01-21

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GattLib version 0.2
Description The issue is related to a stack-based buffer over-read in the gattlib connect function, located in dbus/gattlib.c, due to the misuse of strncpy.
Recommendations For GattLib version 0.2, consider applying a patch that corrects the misuse of strncpy in the gattlib connect function to prevent the buffer over-read.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2019-250

Produtos afetados

Gattlib