VDB
CVE-2011-0530
CVE-2011-0530
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.
EPSS 10.00% · 93.2th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
10.00%
93.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| wouter_verhelst | nbd | 2.9.0, 2.9.1, 2.9.2 |
Timeline
- Feb 22, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Aug 23, 2023 EPSS Score
References
- GLSA-201206-35 vendor-advisory
- https://github.com/yoe/nbd/commit/3ef52043861ab16352d49af89e048ba6339d6df8 url
- 43610 third-party-advisory
- FEDORA-2011-1097 vendor-advisory
- ADV-2011-0403 vdb
- https://bugzilla.redhat.com/show_bug.cgi?id=673562 url
- [oss-security] 20110128 CVE Request -- NDB: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version mailing-list
- SUSE-SR:2011:005 vendor-advisory
- networkblock-nbdserver-bo(65720) vdb
- [oss-security] 20110131 Re: CVE Request -- NDB: CVE-2005-3534 reintroduced in upstream nbd-v2.9.0 version mailing-list
- ADV-2011-0582 vdb
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611187 url
- FEDORA-2011-1108 vendor-advisory
- 46572 vdb
- openSUSE-SU-2011:0193 vendor-advisory
- DSA-2183 vendor-advisory
- 43353 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-0530 advisory