跳转到帖子

FreeBSD: VID-5AFCC9A4-7E04-11EE-8E38-002590C1F29C (CVE-2023-5941): FreeBSD -- libc stdio buffer overflow

recommended_posts

发布于
  • Members

FreeBSD: VID-5AFCC9A4-7E04-11EE-8E38-002590C1F29C (CVE-2023-5941): FreeBSD -- libc stdio buffer overflow

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
11/08/2023
Created
11/14/2023
Added
11/09/2023
Modified
01/28/2025

Description

In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an error.  Depending on the nature of an application that calls libc's stdio functions and the presence of errors returned from the write(2) system call (or an overridden stdio write routine) a heap buffer overflow may occur.Such overflows may lead to data corruption or the execution of arbitrary code at the privilege level of the calling program.

Solution(s)

  • freebsd-upgrade-base-12_4-release-p7
  • freebsd-upgrade-base-13_2-release-p5

References

  • CVE-2023-5941
  • 查看数 706
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…