Описание
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
Отчет
To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. However, this flaw can cause memory corruption, resulting in a denial of service or potentially allowing arbitrary code execution. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.
Меры по смягчению последствий
To mitigate this vulnerability, do not connect to untrusted SFTP servers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gvfs | Affected | ||
| Red Hat Enterprise Linux 6 | gvfs | Affected | ||
| Red Hat Enterprise Linux 7 | gvfs | Affected | ||
| Red Hat Enterprise Linux 8 | gvfs | Affected | ||
| Red Hat Enterprise Linux 9 | gvfs | Affected |
Показывать по
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
(A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
A flaw was found in the SFTP backend in gvfs. When mounting a share an ...
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
8.8 High
CVSS3