7

CVE-2017-1000376

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openshift Version 2.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Libffi Project ≫ Libffi Version < 3.2
Oracle ≫ Peopletools Version 8.56
Oracle ≫ Peopletools Version 8.57
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.389
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
Third Party Advisory
Mailing List
http://www.debian.org/security/2017/dsa-3889
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2017-1000376
Third Party Advisory