Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame
Vulnerability Description
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
BlueZ SBC 缓冲区错误漏洞
Vulnerability Description
BlueZ SBC是BlueZ组织的一个实现蓝牙SBC与mSBC音频编码和解码功能的软件库。 BlueZ SBC存在缓冲区错误漏洞,该漏洞源于SBC frame decoder中的差一错误,允许特制音频有效载荷触发单字节堆越界读取,可能导致邻近的攻击者通过流式蓝牙音频读取相邻堆内存中的单个字节。
CVSS Information
N/A
Vulnerability Type
N/A