PT-2018-13930 · Freebsd · Freebsd
Jakub Jirasek
·
Publicado
2018-11-27
·
Atualizado
2019-01-24
·
CVE-2018-17157
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions prior to 11.2-STABLE(r340854) and prior to 11.2-RELEASE-p5
Description
The issue is caused by an integer overflow error when handling opcodes, which can lead to memory corruption. This can be triggered by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to execute arbitrary code.
Recommendations
For versions prior to 11.2-STABLE(r340854), update to 11.2-STABLE(r340854) or later.
For versions prior to 11.2-RELEASE-p5, update to 11.2-RELEASE-p5 or later.
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freebsd