First published: Mon Jun 19 2017(Updated: )
libc. A memory consumption issue was addressed through improved memory handling.
Credit: CVE-2017-1000373 CVE-2017-1000373 CVE-2017-1000373 CVE-2017-1000373 cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbsd Openbsd | <=6.1 | |
Apple watchOS | <4 | 4 |
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Apple macOS | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2017-1000373 is medium with a severity value of 6.5.
CVE-2017-1000373 is a memory consumption issue in the OpenBSD qsort() function, allowing attackers to consume stack memory and manipulate it.
OpenBSD, Apple macOS High Sierra, Apple tvOS, Apple iOS, and Apple watchOS are affected by CVE-2017-1000373.
An attacker can construct a malicious input array that causes the qsort() function to recurse a large number of times, consuming stack memory and potentially manipulating it.
Yes, you can find more information about CVE-2017-1000373 at the following references: http://www.securityfocus.com/bid/99177, http://www.securitytracker.com/id/1039427, https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/qsort.c?rev=1.15&content-type=text/x-cvsweb-markup