Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-1000373
Description:The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-1000373
BugTraq ID: 99177
http://www.securityfocus.com/bid/99177
https://www.exploit-db.com/exploits/42271/
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&content-type=text/x-cvsweb-markup
https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt
http://www.securitytracker.com/id/1039427




© 1998-2025 E-Soft Inc. All rights reserved.