PYSEC-2019-250

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/gattlib-py/PYSEC-2019-250.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2019-250
Withdrawn
2024-11-22T04:37:04Z
Published
2019-01-21T06:29:00Z
Modified
2024-11-21T14:22:50.820785Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.

References

Affected packages

PyPI / gattlib-py

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.4.10
0.4.11
0.4.12
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/gattlib-py/PYSEC-2019-250.yaml"