CVE-2017-6952: Integer Overflow
Integer overflow in the cswinkernelmalloc function in winkernelmm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/capstoneto a version that resolves this vulnerability.Fixed in 3.0.5rc2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6952?
CVE-2017-6952 has a high severity as it allows for a denial of service through a heap-based buffer overflow in a kernel driver.
How do I fix CVE-2017-6952?
To fix CVE-2017-6952, upgrade to Capstone version 3.0.5rc2 or later.
Which versions of Capstone are affected by CVE-2017-6952?
CVE-2017-6952 affects Capstone versions 3.0.4 and earlier.
What type of vulnerability is CVE-2017-6952?
CVE-2017-6952 is an integer overflow vulnerability that can result in a buffer overflow.
Can CVE-2017-6952 lead to arbitrary code execution?
CVE-2017-6952 is primarily associated with denial of service and may have other unspecified impacts, but it does not directly indicate arbitrary code execution.