Stack Memory Vulnerability in NetBSD's Sorting Function
CVE-2017-1000378

9.8CRITICAL

Key Information:

Vendor

Netbsd

Status
Vendor
CVE Published:
19 June 2017

What is CVE-2017-1000378?

The qsort() function in NetBSD is vulnerable due to its recursive and non-randomized nature. Attackers can craft a specific input array that exploits this vulnerability, leading to excessive recursion and consuming significant stack memory. This can pave the way for arbitrary code execution, allowing malicious actors to manipulate the stack and execute unauthorized code. This issue impacts NetBSD version 7.1 and potentially earlier releases.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.