← Back

CVE-2020-7457

nvd nist
Published: Jul 9, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

Affected (21)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.3
Version 11.3 p10
Version 11.3 p1
Version 11.3 p2
Version 11.3 p3
Version 11.3 p4
Version 11.3 p5
Version 11.3 p6
Version 11.3 p7
Version 11.3 p8
Version 11.3 p9
Version 11.4
Version 11.4 beta1
Version 11.4 rc2
Version 12.1
Version 12.1 p1
Version 12.1 p2
Version 12.1 p3
Version 12.1 p4
Version 12.1 p5
Version 12.1 p6

References (6)

Source: secteam@freebsd.org
PatchVendor Advisory
Source: secteam@freebsd.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.