Parent: 800257a5aae104ba73c5d299cd350643610998b0
Author: Matias Karhumaa <matias.karhumaa@gmail.com>
Committer: Johan Hedberg <johan.hedberg@intel.com>
Date: 2018-10-18 19:10:36
Tree: b201e812ce7a18103813b72bdcdc305a24d5a693
btmon: fix segfault caused by buffer over-read Fix segfault caused by buffer over-read in service_rsp function of monitor/sdp.c. This bug can be triggered locally reading malformed btmon capture file and also over the air by sending specifically crafted SDP Search Attribute response to device running btmon. Bug was found by fuzzing btmon with AFL.
Diffstat
| M | monitor/sdp.c | | | 4 | ++++ |
1 files changed, 4 insertions(+), 0 deletions(-)