CVE-2017-1000373
OpenBSD - 'at Stack Clash' Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.
La función qsort() de OpenBSD es recursiva y no aleatorizada, por lo que un atacante puede construir un array de entrada patológica de elementos N que provoca que qsort() se repita inevitablemente N/4 veces. Esto permite que los atacantes consuman cantidades de memoria de pila arbitrarias y manipulen la memoria de pila para ayudar en los ataques de ejecución de código arbitrario. Esto afecta a OpenBSD 6.1 y, posiblemente, a versiones anteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-19 CVE Reserved
- 2017-06-19 CVE Published
- 2023-05-30 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99177 | Third Party Advisory | |
http://www.securitytracker.com/id/1039427 | Vdb Entry | |
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&content-type=text/x-cvsweb-markup | Mitigation | |
https://support.apple.com/HT208112 | X_refsource_confirm | |
https://support.apple.com/HT208113 | X_refsource_confirm | |
https://support.apple.com/HT208115 | X_refsource_confirm | |
https://support.apple.com/HT208144 | X_refsource_confirm | |
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42271 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|