CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
48.9%
In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objectsβ write space members for write-buffered streams when the write(2) system call returns an error. Β Depending on the nature of an application that calls libcβs stdio functions and the presence of errors returned from the write(2) system call (or an overridden stdio write routine) a heap buffer overflow may occur. Such overflows may lead to data corruption or the execution of arbitrary code at the privilege level of the calling program.
Vendor | Product | Version | CPE |
---|---|---|---|
freebsd | freebsd | * | cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p1:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p2:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p3:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p4:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p5:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p6:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:* |
freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:* |