CVE-2020-7455 Information
Feb 14, 2021
cve
Description
In FreeBSD 12.1-STABLE before r360973 12.1-RELEASE before p5 11.4-STABLE before r360973 11.4-BETA1 before p1 and 11.3-RELEASE before p9 the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:13.libalias.asc https://security.netapp.com/advisory/ntap-20200518-0005/ https://www.zerodayinitiative.com/advisories/ZDI-20-661/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: