First published: Tue Dec 04 2018(Updated: )
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to execute arbitrary code.
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | <11.2 | |
FreeBSD Kernel | =11.2-p4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17157 has a critical severity as it allows unprivileged remote users to execute arbitrary code.
To fix CVE-2018-17157, upgrade FreeBSD to version 11.2-STABLE(r340854) or 11.2-RELEASE-p5 or later.
CVE-2018-17157 affects users running FreeBSD versions prior to 11.2-STABLE(r340854) and 11.2-RELEASE-p5.
CVE-2018-17157 is an integer overflow vulnerability related to NFSv4 request handling.
Yes, CVE-2018-17157 can be exploited remotely by unprivileged users accessing the NFS server.