Stack-based buffer overflow in ConnMan - CVE-2021-33833
Published: June 9, 2021 / Updated: September 19, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the dnsproxy component in the uncompress function when unpacking NAME and RDATA/RDLENGTH fields with TYPE A/AAAA. A remote attacker can send specially crafted DNS packet to the ConnMan and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
connman (Ubuntu package)
How to mitigate CVE-2021-33833
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1