« Volver al listado

CVE-2006-3146

Estado: ModificadaMedia (5)—

The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrated by BlueSmack. NOTE: this issue was originally reported for 4.00.23.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3146",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-22T22:06:00.000",
  "references": [
    {
      "url": "http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://attrition.org/pipermail/vim/2006-October/001085.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://briankrebswatch.blogspot.com/2006/10/more-on-toshiba-patches.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20657",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016345",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://trifinite.org/blog/archives/2006/06/update_tosiba_a.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://trifinite.org/trifinite_advisory_toshiba.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/26686",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/437811/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/18527",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27228",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://attrition.org/pipermail/vim/2006-October/001085.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://briankrebswatch.blogspot.com/2006/10/more-on-toshiba-patches.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20657",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016345",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://trifinite.org/blog/archives/2006/06/update_tosiba_a.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://trifinite.org/trifinite_advisory_toshiba.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/26686",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/437811/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/18527",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27228",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to \"Ping o' Death\" and as demonstrated by BlueSmack.  NOTE: this issue was originally reported for 4.00.23."
    },
    {
      "lang": "es",
      "value": "El controlador TOSRFBD.SYS para Toshiba Bluetooth Stack v4.00.29 y anteriores en Windows permite a atacantes remotos provocar una denegación de servicio (reinicio) a través de una solicitud L2CAP echo que provoca una acceso \"fuera de rango\" a memoria, similar al \"Ping  de la Muerte\" tal y como lo demuestra BlueSmack. NOTA: este problema fue reportado originalmente para v4.00.23.\r\n"
    }
  ],
  "lastModified": "2026-06-16T22:26:29.593",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA66D53B-0896-4427-82C1-A43273F1CB56",
              "versionEndIncluding": "4.00.29"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.00.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0A3CCBE-29F6-4833-9839-0CEAB0C33A2B"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.00.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FB969B2-F6B7-48C0-9B4D-EC9F92944CA4"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.00.31a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "950ACF9E-0783-42E5-A804-18A9F26E038A"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.00.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8D00C96-6DA5-453F-A7E2-694E0B83D68E"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.01.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A2ACFAD-8406-4478-8D12-F4EC8684728C"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.10.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6160E18A-DE9C-4D0A-A901-BC2BB1CE3F26"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.20.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01049F3C-7EE1-4836-BF9C-C2CFE84A03D7"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.20.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "484C6E65-24BA-4D07-8BD1-71384E63F41D"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.20.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "083F6F9A-626B-4F7B-9804-3E97C0D8624F"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:3.20.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F031926C-3138-4D5E-81F4-ED34C95367C2"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:4.00.01t:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17E31608-3811-491C-9759-6F66D0B4C6E2"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:4.00.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "611EB66B-01DA-43DE-8DFE-0D6F5AD0657A"
            },
            {
              "criteria": "cpe:2.3:a:toshiba:bluetooth_stack:4.00.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "952E2AD5-508B-4FEE-8417-5F9611EA886E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}