Количество 3
Количество 3
CVE-2017-1000378
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.
GHSA-qc88-87cw-xw5j
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.
BDU:2017-01589
Уязвимость функции qsort операционной системы NetBSD, позволяющая нарушителю выполнить произвольный код (расходование памяти)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-1000378 The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions. | CVSS3: 9.8 | 4% Низкий | больше 8 лет назад | |
GHSA-qc88-87cw-xw5j The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад | |
BDU:2017-01589 Уязвимость функции qsort операционной системы NetBSD, позволяющая нарушителю выполнить произвольный код (расходование памяти) | CVSS2: 7.5 | 4% Низкий | больше 8 лет назад |
Уязвимостей на страницу