Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83xj-2vf9-49hq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execution. A guest OS using a firmware image can cause the bhyve process to crash, or possibly execute arbitrary code on the host as root.

In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execution. A guest OS using a firmware image can cause the bhyve process to crash, or possibly execute arbitrary code on the host as root.

EPSS

Процентиль: 73%
0.00791
Низкий

10 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 10
nvd
около 7 лет назад

In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execution. A guest OS using a firmware image can cause the bhyve process to crash, or possibly execute arbitrary code on the host as root.

CVSS3: 10
fstec
около 7 лет назад

Уязвимость операционных систем FreeBSD, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю перезаписывать память на хосте bhyve или выполнить произвольный код от имени пользователя root

EPSS

Процентиль: 73%
0.00791
Низкий

10 Critical

CVSS3

Дефекты

CWE-787