#VU216 Heap overflow in processing patch files in FreeBSD and macOS - CVE-2014-9862

 

#VU216 Heap overflow in processing patch files in FreeBSD and macOS - CVE-2014-9862

Published: July 26, 2016 / Updated: January 13, 2017


Vulnerability identifier: #VU216
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:C/VI:C/VA:C/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2014-9862
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FreeBSD
macOS
Software vendor:
FreeBSD Foundation
Apple Inc.

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in FreeBSD bsdiff. A remote unauthenticated attacker can cause a heap overflow by creating a specially crafted patch file loaded by the target user via bspatch.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation


External links