PT-2005-5578 · Network Block Device+2 · Nbd-Client+3

Kurt Fitzner

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2005-3534

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nbd-server versions 2.7.5 and earlier nbd-server versions 2.8.0 through 2.8.2 nbd-client versions prior to 2.8.2-r1
Description The issue affects the nbd-server and nbd-client packages in Debian GNU/Linux and Gentoo Linux operating systems. It allows remote attackers to exploit multiple vulnerabilities, potentially leading to breaches of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely. A buffer overflow in the Network Block Device (nbd) server is caused by a large request that is written past the end of the buffer because nbd does not account for memory taken by the reply header.
Recommendations For nbd-server versions 2.7.5 and earlier, update to a version later than 2.7.5. For nbd-server versions 2.8.0 through 2.8.2, update to a version later than 2.8.2. For nbd-client versions prior to 2.8.2-r1, update to version 2.8.2-r1 or later. As a temporary workaround, consider restricting access to the nbd-server and nbd-client to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02784
BDU:2015-02785
BDU:2015-09488
CVE-2005-3534
DSA-924-1
OPENSUSE-SU-2024:11077-1

Affected Products

Debian
Gentoo Linux
Nbd-Client
Nbd-Server