In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/101191 | Third Party Advisory VDB Entry |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 | Issue Tracking Vendor Advisory |
https://svnweb.freebsd.org/base?view=revision&revision=324102 | Issue Tracking Vendor Advisory |
http://www.securityfocus.com/bid/101191 | Third Party Advisory VDB Entry |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222687 | Issue Tracking Vendor Advisory |
https://svnweb.freebsd.org/base?view=revision&revision=324102 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2017-10-05 07:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-15037
Mitre link : CVE-2017-15037
CVE.ORG link : CVE-2017-15037
JSON object : View
Products Affected
freebsd
- freebsd