CVE-2005-3534
published 2005-12-22CVE-2005-3534: Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.99%
92.5th percentile
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nbd | < nbd 1:2.9.16-8 (bookworm) | nbd 1:2.9.16-8 (bookworm) |
| debian | nbd | < nbd 1:2.8.3-1 (bookworm) | nbd 1:2.8.3-1 (bookworm) |
| wouter_verhelst | nbd | <= 2.7.5 | — |
| wouter_verhelst | nbd | <= 2.9.19 | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
| wouter_verhelst | nbd | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-0530: nbd - Buffer overflow in the mainloop function in nbd-server.c in the server in Networ...
vendor_debian·2011·CVSS 7.5
CVE-2011-0530 [HIGH] CVE-2011-0530: nbd - Buffer overflow in the mainloop function in nbd-server.c in the server in Networ...
Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
Scope: local
bookworm: resolved (fixed in 1:2.9.16-8)
bullseye: resolved (fixed in 1:2.9.16-8)
forky: resolved (fixed in 1:2.9.16-8)
sid: resolved (fixed in 1:2.9.16-8)
trixie: resolved (fixed in 1:2.9.16-8)
Debian
CVE-2005-3534: nbd - Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and ...
vendor_debian·2005·CVSS 7.5
CVE-2005-3534 [HIGH] CVE-2005-3534: nbd - Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and ...
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
Scope: local
bookworm: resolved (fixed in 1:2.8.3-1)
bullseye: resolved (fixed in 1:2.8.3-1)
forky: resolved (fixed in 1:2.8.3-1)
sid: resolved (fixed in 1:2.8.3-1)
trixie: resolved (fixed in 1:2.8.3-1)
GHSA
GHSA-8p8p-8qmp-rfr2: Buffer overflow in the mainloop function in nbd-server
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-0530 [HIGH] CWE-119 GHSA-8p8p-8qmp-rfr2: Buffer overflow in the mainloop function in nbd-server
Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
GHSA
GHSA-96w8-f5p6-mqmw: Buffer overflow in the Network Block Device (nbd) server 2
ghsa_unreviewed·2022-05-01
CVE-2005-3534 [HIGH] CWE-119 GHSA-96w8-f5p6-mqmw: Buffer overflow in the Network Block Device (nbd) server 2
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
OSV
CVE-2011-0530: Buffer overflow in the mainloop function in nbd-server
osv·2011-02-22·CVSS 7.5
CVE-2011-0530 [HIGH] CVE-2011-0530: Buffer overflow in the mainloop function in nbd-server
Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
OSV
CVE-2005-3534: Buffer overflow in the Network Block Device (nbd) server 2
osv·2005-12-22·CVSS 7.5
CVE-2005-3534 [HIGH] CVE-2005-3534: Buffer overflow in the Network Block Device (nbd) server 2
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0530 NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version
bugzilla·2011-01-28·CVSS 7.5
CVE-2011-0530 [HIGH] CVE-2011-0530 NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version
CVE-2011-0530 NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version
Originally, CVE-2005-3534:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3534
has been assigned to NBD and addressed in nbd-v2.8.3 version:
[2] http://sourceforge.net/project/shownotes.php?release_id=380202&group_id=13229
via changeset:
[3] https://github.com/yoe/nbd/commit/4ed24fe0d64c7cc9963c57b52cad1555ad7c6b60
But nbd-v2.9.0:
[4] http://sourceforge.net/projects/nbd/files/nbd/2.9.0/
contains the issue again. This flaw was fixed second time
via upstream changeset:
[5] https://github.com/yoe/nbd/commit/3ef52043861ab16352d49af89e048ba6339d6df8
References:
[6] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611187
Discussion:
This issue affects the versions of the nbd package, as shipped
with
Bugzilla
NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version [fedora-all]
bugzilla·2011-01-28·CVSS 7.5
CVE-2005-3534 [HIGH] NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version [fedora-all]
NBD: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=673562
Please note: this issue affects multipl
http://bugs.gentoo.org/show_bug.cgi?id=116314http://secunia.com/advisories/18135http://secunia.com/advisories/18171http://secunia.com/advisories/18209http://secunia.com/advisories/18315http://secunia.com/advisories/18503http://secunia.com/advisories/43353http://secunia.com/advisories/43610http://sourceforge.net/mailarchive/forum.php?thread_id=9201144&forum_id=40388http://sourceforge.net/project/shownotes.php?release_id=380202&group_id=13229http://sourceforge.net/project/shownotes.php?release_id=380210&group_id=13229http://www.debian.org/security/2005/dsa-924http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlhttp://www.osvdb.org/21848http://www.securityfocus.com/bid/16029https://usn.ubuntu.com/237-1/http://bugs.gentoo.org/show_bug.cgi?id=116314http://secunia.com/advisories/18135http://secunia.com/advisories/18171http://secunia.com/advisories/18209http://secunia.com/advisories/18315http://secunia.com/advisories/18503http://secunia.com/advisories/43353http://secunia.com/advisories/43610http://sourceforge.net/mailarchive/forum.php?thread_id=9201144&forum_id=40388http://sourceforge.net/project/shownotes.php?release_id=380202&group_id=13229http://sourceforge.net/project/shownotes.php?release_id=380210&group_id=13229http://www.debian.org/security/2005/dsa-924http://www.gentoo.org/security/en/glsa/glsa-200512-14.xmlhttp://www.osvdb.org/21848http://www.securityfocus.com/bid/16029https://usn.ubuntu.com/237-1/
2005-12-22
Published