GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/46215/ | third party advisory vdb entry exploit |
https://github.com/labapart/gattlib/issues/82 | third party advisory issue tracking exploit |
https://github.com/labapart/gattlib/issues/81 | third party advisory issue tracking exploit |