CVE-2011-0530

Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request.  NOTE: this issue exists because of a CVE-2005-3534 regression.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
wouter_verhelstnbd
𝑥
≤ 2.9.19
wouter_verhelstnbd
2.9.0
wouter_verhelstnbd
2.9.1
wouter_verhelstnbd
2.9.2
wouter_verhelstnbd
2.9.3
wouter_verhelstnbd
2.9.4
wouter_verhelstnbd
2.9.5
wouter_verhelstnbd
2.9.6
wouter_verhelstnbd
2.9.7
wouter_verhelstnbd
2.9.8
wouter_verhelstnbd
2.9.9
wouter_verhelstnbd
2.9.10
wouter_verhelstnbd
2.9.11
wouter_verhelstnbd
2.9.12
wouter_verhelstnbd
2.9.13
wouter_verhelstnbd
2.9.14
wouter_verhelstnbd
2.9.15
wouter_verhelstnbd
2.9.16
wouter_verhelstnbd
2.9.17
wouter_verhelstnbd
2.9.18
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nbd
bullseye (security)
1:3.21-1+deb11u1
fixed
bullseye
1:3.21-1+deb11u1
fixed
etch
not-affected
bookworm
1:3.24-1.1
fixed
sid
1:3.26.1-6
fixed
trixie
1:3.26.1-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nbd
natty
Fixed 1:2.9.16-7.1ubuntu2
released
maverick
Fixed 1:2.9.14-2ubuntu1.10.10.1
released
lucid
Fixed 1:2.9.14-2ubuntu1.10.04.1
released
karmic
ignored
hardy
ignored
dapper
not-affected
References