这段文本描述的是一个 BlueZ 蓝牙协议栈中的安全漏洞。以下是专业且准确的中文翻译: BlueZ A2DP 协议栈基于栈的缓冲区溢出导致的远程代码执行漏洞 该漏洞允许处于网络相邻位置的攻击者在受影响的 BlueZ 安装环境中执行任意代码。为了利用此漏洞,攻击者必须首先能够将一个恶意的蓝牙设备与目标系统进行配对。 具体的缺陷存在于流端点(stream endpoints)的处理逻辑中。该问题源于在将用户提供的数据复制到固定长度的栈缓冲区之前,未对数据长度进行适当校验。攻击者可利用此漏洞在 root 用户上下文中执行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet