CVE-2008-2374
9.8 · CRITICALOverview
CVE-2008-2374 is a critical-severity vulnerability affecting bluez bluez-libs. It was published on July 7, 2008 and has a CVSS 3.1 base score of 9.8 (CRITICAL).
This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.
Remediation
Check the references section for vendor advisories and patches from bluez. Update bluez-libs to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| bluez | bluez-libs | >= 0, < 3.34 | Affected |
| bluez | bluez-utils | >= 0, < 3.34 | Affected |
References
Frequently Asked Questions
What is CVE-2008-2374?
CVE-2008-2374 is a critical-severity vulnerability affecting bluez bluez-libs. It was published on July 7, 2008 and has a CVSS 3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2008-2374?
This vulnerability has a CVSS 3.1 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2008-2374?
Check the references section for vendor advisories and patches from bluez. Update bluez-libs to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2008-2374?
CyberStrike's AI-powered security agents can automatically detect CVE-2008-2374 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related CRITICAL CVEs from 2008
View all →Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which al
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed w
Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execu
EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypas
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remot
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute ar
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses p