Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c77x-v69r-5vpg

Опубликовано: 05 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

EPSS

Процентиль: 14%
0.00046
Низкий

8.4 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.4
nvd
больше 1 года назад

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

EPSS

Процентиль: 14%
0.00046
Низкий

8.4 High

CVSS3

Дефекты

CWE-125