cturt.github.io
http://cturt.github.io/sendmsg.html CVE-2016-1887
HIGH
FreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)
Record summary
CVE-2016-1887 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)ExploitDB exploitby CTurtNot analyzed1 file
References
41035906vdb entry
http://www.securitytracker.com/id/1035906 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-1887 FreeBSD-SA-16:19Vendor advisory
https://security.freebsd.org/advisories/FreeBSD-SA-16:19.sendmsg.asc