In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:12.libalias.asc | vendor advisory |
https://security.netapp.com/advisory/ntap-20200518-0005/ | third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-660/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-659/ | vdb entry third party advisory |