In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.
References
Link | Resource |
---|---|
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 | Issue Tracking Vendor Advisory |
https://svnweb.freebsd.org/base?view=revision&revision=324102 | Issue Tracking Vendor Advisory |
http://www.securityfocus.com/bid/101191 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-10-05 00:29
Updated : 2017-10-13 12:58
NVD link : CVE-2017-15037
Mitre link : CVE-2017-15037
JSON object : View
CWE
Products Affected
freebsd
- freebsd