Vulnerability Name: | CVE-2017-1000374 (CCN-127458) | ||||||||||||
Assigned: | 2017-06-19 | ||||||||||||
Published: | 2017-06-19 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
7.4 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1000374 Source: BID Type: Third Party Advisory, VDB Entry 99176 Source: CCN Type: BID-99176 NetBSD CVE-2017-1000374 Security Bypass Vulnerability Source: XF Type: UNKNOWN netbsd-cve20171000374-code-exec(127458) Source: CCN Type: NetBSD Web site NetBSD Source: CCN Type: Qualys Security Advisory QSA - 2017-06-19 The Stack Clash Source: MISC Type: Mailing List, Third Party Advisory https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |