Arbitrary code execution in FreeBSD - #VU824
Published: October 10, 2016 / Updated: October 11, 2016
Vulnerability identifier: #VU824
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated user to cause arbitrary code execution on the target system.
The weakness occurs in bspatch and exists due to insufficient input validation. By creating and sending a specially crafted patch file attackers can trigger a heap overflow and execute arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
The weakness occurs in bspatch and exists due to insufficient input validation. By creating and sending a specially crafted patch file attackers can trigger a heap overflow and execute arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Affected software
FreeBSD
Remediation
Update patched versions
https://security.FreeBSD.org/patches/SA-16:29/bspatch.patch
https://security.FreeBSD.org/patches/SA-16:29/bspatch.patch