2.1
CVSSv2

CVE-2021-3588

Published: 10/06/2021 Updated: 29/10/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bluez bluez

Vendor Advisories

Debian Bug report logs - #989700 bluez: CVE-2021-3588 Package: src:bluez; Maintainer for src:bluez is Debian Bluetooth Maintainers <team+pkg-bluetooth@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 10 Jun 2021 19:27:01 UTC Severity: grave Tags: patch, pending, security, upstream ...
A security issue has been found in BlueZ before version 556 The cli_feat_read_cb() function in src/gatt-databasec does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading ...