← Back

CVE-2021-29630

nvd nist
Published: Aug 30, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially execute arbitrary code.

Affected (29)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.4
Version 11.4 p10
Version 11.4 p11
Version 11.4 p12
Version 11.4 p13
Version 11.4 p1
Version 11.4 p2
Version 11.4 p3
Version 11.4 p4
Version 11.4 p5
Version 11.4 p6
Version 11.4 p7
Version 11.4 p8
Version 11.4 p9
Version 12.2
Version 12.2 p10
Version 12.2 p1
Version 12.2 p2
Version 12.2 p3
Version 12.2 p4
Version 12.2 p5
Version 12.2 p6
Version 12.2 p7
Version 12.2 p8
Version 12.2 p9
Version 13.0
Version 13.0 p1
Version 13.0 p2
Version 13.0 p3

References (4)

Source: secteam@freebsd.org
PatchVendor Advisory
Source: secteam@freebsd.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.