peter bassill · operator
$ cve CVE-2017-1000373 JSON

CVE-2017-1000373 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 13.4% (pctl 96)

Patch early

A public exploit exists.

Description

The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS13.38% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-400
On CISA KEVno
Public exploityes
Published2017-06-19
Last modified2026-06-17

Affected (1)

VendorProduct
openbsdopenbsd

Public exploits

SourceTitleDate
exploit-dbOpenBSD - 'at Stack Clash' Local Privilege Escalation2017-06-28

References

→ the Explorer  ·  watch your stack  ·  NVD