PT-2012-1264 · Freebsd Project/The Netbsd Foundation+3 · Libc+3

Publicado

2012-07-25

·

Atualizado

2012-07-26

·

CVE-2007-6754

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions jemalloc in libc for FreeBSD version 6.4 jemalloc in libc for NetBSD (affected versions not specified)
Description The issue is related to the ipalloc function in libc/stdlib/malloc.c which does not properly allocate memory. This can make it easier for attackers to perform memory-related attacks, such as buffer overflows, via a large size value. The issue is related to "integer rounding and overflow" errors.
Recommendations For jemalloc in libc for FreeBSD version 6.4, consider updating to a version that properly allocates memory to prevent memory-related attacks. For jemalloc in libc for NetBSD, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6754

Produtos afetados

Freebsd
Netbsd
Jemalloc
Libc