← Back to browse · API

CVE-2008-2374

Severity
CRITICAL
CVSS
9.8
EPSS
0.04287
Risk score
40.7
CISA KEV
No
PoC
No
Published
2008-07-07
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2008-2369, GHSA-278X-6VG6-6G42
Products
n/a:n/a n/a
Sources
euvd EUVD-2008-2369

Description

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

References