Stack-based buffer overflow in ConnMan - CVE-2021-26675

 

Stack-based buffer overflow in ConnMan - CVE-2021-26675

Published: February 12, 2021


Vulnerability identifier: #VU50670
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26675
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within dnsproxy in ConnMan. A remote unauthenticated attacker on the local network can send specially crafted packets to the affected system, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

ConnMan
Arch Linux
Gentoo Linux
Ubuntu
connman (Debian package)
connman (Ubuntu package)

How to mitigate CVE-2021-26675

Install updates from vendor's website.

ConnMan - update to 1.39
connman (Debian package) - update to 1.36-2.1~deb10u1
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1

External References

Related Security Bulletins