Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.
References
Configurations
History
21 Nov 2024, 03:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/97323 - | |
References | () https://github.com/aquynh/capstone/commit/6fe86eef621b9849f51a5e1e5d73258a93440403 - Patch |
Information
Published : 2017-03-16 21:59
Updated : 2024-11-21 03:30
NVD link : CVE-2017-6952
Mitre link : CVE-2017-6952
CVE.ORG link : CVE-2017-6952
JSON object : View
Products Affected
capstone-engine
- capstone
CWE
CWE-190
Integer Overflow or Wraparound