Lucene search

K
cveFreebsdCVE-2020-7457
HistoryJul 09, 2020 - 2:15 p.m.

CVE-2020-7457

2020-07-0914:15:10
CWE-362
CWE-662
CWE-416
freebsd
web.nvd.nist.gov
117
2
cve-2020-7457
freebsd
code execution
memory modification
nvd
security vulnerability
race condition

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.397

Percentile

97.3%

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

Affected configurations

Nvd
Node
freebsdfreebsdMatch11.3-
OR
freebsdfreebsdMatch11.3p1
OR
freebsdfreebsdMatch11.3p10
OR
freebsdfreebsdMatch11.3p2
OR
freebsdfreebsdMatch11.3p3
OR
freebsdfreebsdMatch11.3p4
OR
freebsdfreebsdMatch11.3p5
OR
freebsdfreebsdMatch11.3p6
OR
freebsdfreebsdMatch11.3p7
OR
freebsdfreebsdMatch11.3p8
OR
freebsdfreebsdMatch11.3p9
OR
freebsdfreebsdMatch11.4-
OR
freebsdfreebsdMatch11.4beta1
OR
freebsdfreebsdMatch11.4rc2
OR
freebsdfreebsdMatch12.1-
OR
freebsdfreebsdMatch12.1p1
OR
freebsdfreebsdMatch12.1p2
OR
freebsdfreebsdMatch12.1p3
OR
freebsdfreebsdMatch12.1p4
OR
freebsdfreebsdMatch12.1p5
OR
freebsdfreebsdMatch12.1p6
VendorProductVersionCPE
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p10:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p2:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p3:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p4:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p5:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p6:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p7:*:*:*:*:*:*
freebsdfreebsd11.3cpe:2.3:o:freebsd:freebsd:11.3:p8:*:*:*:*:*:*
Rows per page:
1-10 of 211

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "FreeBSD 12.1-RELEASE before p7, 11.4-RELEASE before p1, 11.3-RELEASE before p11"
      }
    ]
  }
]

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.397

Percentile

97.3%