CVE-2017-1000373
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 15%
from disclosure to weapon9 days
Published on NVDJun 19
1st PoC+9d
exploitation probability
15%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/42271cve_referencewww.exploit-db.com/exploits/42271/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&content-type=text/x-cvsweb-markuphttps://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://www.exploit-db.com/exploits/42271/https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txthttp://www.securityfocus.com/bid/99177http://www.securitytracker.com/id/1039427