Out-of-bounds write in IBM AIX - CVE-2017-6451
Published: July 7, 2017
Vulnerability identifier: #VU7385
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6451
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The weakness exists due to improper handling of the return value of the snprintf function by the mx4200_send function in the legacy MX4200 refclock in NTP. A local attacker can trigger out-of-bounds memory write and execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to improper handling of the return value of the snprintf function by the mx4200_send function in the legacy MX4200 refclock in NTP. A local attacker can trigger out-of-bounds memory write and execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
IBM AIX
Amazon Linux AMI
Junos OS
Slackware Linux
Fedora
Junos OS Evolved
ntp
How to mitigate CVE-2017-6451
Install update from vendor's website.
Junos OS - addressed in versions 12.3X48-D95, 12.3R12-S15, 14.1X53-D53, 15.1x49-D190, 15.1R7-S6, 16.1R7-S6, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.4R2-S7, 17.4R3, 18.1R3-S8, 18.2R2-S7, 18.2R3-S1, 18.3R1-S5, 18.3R2-S2, 18.3R3, 18.4R1-S4, 18.4R2-S1, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1
ntp - addressed in versions 4.2.6p5-44.fc24, 4.2.6p5-44.fc25, 4.2.8p10-1.fc26
Junos OS Evolved - update to 20.1R1-EVO
ntp - addressed in versions 4.2.6p5-44.fc24, 4.2.6p5-44.fc25, 4.2.8p10-1.fc26
Junos OS Evolved - update to 20.1R1-EVO