Lucene search

K
cvelistFreebsdCVELIST:CVE-2020-7458
HistoryJul 09, 2020 - 1:47 p.m.

CVE-2020-7458

2020-07-0913:47:03
freebsd
www.cve.org
1

9.9 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%

In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arbitrary code execution.

CNA Affected

[
  {
    "product": "FreeBSD",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "FreeBSD 11.4-RELEASE before p1"
      }
    ]
  }
]

9.9 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%

Related for CVELIST:CVE-2020-7458