In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/101191 | Third Party Advisory VDB Entry |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 | Issue Tracking Vendor Advisory |
https://svnweb.freebsd.org/base?view=revision&revision=324102 | Issue Tracking Vendor Advisory |
http://www.securityfocus.com/bid/101191 | Third Party Advisory VDB Entry |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 | Issue Tracking Vendor Advisory |
https://svnweb.freebsd.org/base?view=revision&revision=324102 | Issue Tracking Vendor Advisory |
Configurations
History
21 Nov 2024, 03:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/101191 - Third Party Advisory, VDB Entry | |
References | () https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 - Issue Tracking, Vendor Advisory | |
References | () https://svnweb.freebsd.org/base?view=revision&revision=324102 - Issue Tracking, Vendor Advisory |
Information
Published : 2017-10-05 07:29
Updated : 2024-11-21 03:13
NVD link : CVE-2017-15037
Mitre link : CVE-2017-15037
CVE.ORG link : CVE-2017-15037
JSON object : View
Products Affected
freebsd
- freebsd