CVE-2021-36082

NameCVE-2021-36082
Descriptionntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs990528

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ndpi (PTS)jessie1.5.0-1vulnerable
stretch (security), stretch (lts), stretch1.8-1+deb9u1fixed
buster2.6-3fixed
buster (security)2.6-3+deb10u1fixed
trixie, bookworm4.2-2fixed
sid4.2-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ndpisourcejessie(unfixed)end-of-life
ndpisourcestretch(not affected)
ndpisourcebuster(not affected)
ndpisource(unstable)4.0-1990528

Notes

[buster] - ndpi <not-affected> (Vulnerable code not present)
[stretch] - ndpi <not-affected> (Vulnerable code added later)
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=30393
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ndpi/OSV-2021-304.yaml
https://github.com/ntop/nDPI/commit/1ec621c85b9411cc611652fd57a892cfef478af3

Search for package or bug name: Reporting problems