CVE-2017-1000375
CRITICALNetBSD < 7.1 - Arbitrary Code Execution via Stack Clash
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-1000375. PoCs published by Qualys Corporation.
AI-analyzed exploit summary This exploit triggers a stack overflow in NetBSD's stack gap handling (CVE-2017-1000375) by recursively smashing the stack with a large buffer. It is designed to cause a denial-of-service (DoS) via stack exhaustion.
Description
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.
Exploits (1)
This exploit triggers a stack overflow in NetBSD's stack gap handling (CVE-2017-1000375) by recursively smashing the stack with a large buffer. It is designed to cause a denial-of-service (DoS) via stack exhaustion.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H