PT-2012-1264 · Freebsd Project/The Netbsd Foundation+3 · Libc+3
Publicado
2012-07-25
·
Atualizado
2012-07-26
·
CVE-2007-6754
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
jemalloc in libc for FreeBSD version 6.4
jemalloc in libc for NetBSD (affected versions not specified)
Description
The issue is related to the
ipalloc function in libc/stdlib/malloc.c which does not properly allocate memory. This can make it easier for attackers to perform memory-related attacks, such as buffer overflows, via a large size value. The issue is related to "integer rounding and overflow" errors.Recommendations
For jemalloc in libc for FreeBSD version 6.4, consider updating to a version that properly allocates memory to prevent memory-related attacks.
For jemalloc in libc for NetBSD, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freebsd
Netbsd
Jemalloc
Libc