NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.
References
Link | Resource |
---|---|
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | Exploit Third Party Advisory |
http://www.securityfocus.com/bid/99257 | Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/42272/ |
Configurations
Information
Published : 2017-06-19 09:29
Updated : 2017-08-11 18:29
NVD link : CVE-2017-1000375
Mitre link : CVE-2017-1000375
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
netbsd
- netbsd