Description
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
26.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-772
Status
published
Products (3)
freebsd/freebsd
11.3 (9 CPE variants)
freebsd/freebsd
11.4 (2 CPE variants)
freebsd/freebsd
12.1 (5 CPE variants)
Published
May 13, 2020
Tracked Since
Feb 18, 2026