CVE-2017-1084
HIGHFreeBSD < 11.2 - Stack-Based Buffer Overflow via Stack Guard-Page Bypass
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-1084. PoCs published by Qualys Corporation.
AI-analyzed exploit summary This exploit targets a memory management vulnerability in FreeBSD (CVE-2017-1084) by exhausting memory mappings and triggering a stack clash. It demonstrates a local privilege escalation by corrupting memory boundaries.
Description
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.
Exploits (2)
This exploit targets a memory management vulnerability in FreeBSD (CVE-2017-1084) by exhausting memory mappings and triggering a stack clash. It demonstrates a local privilege escalation by corrupting memory boundaries.
This exploit targets a stack clash vulnerability in FreeBSD (CVE-2017-1084) by manipulating stack growth and memory allocation to trigger a collision. It uses recursive functions and memory mapping to achieve local privilege escalation.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H