Vulnerabilities > CVE-2017-1000372 - Security Bypass vulnerability in OpenBSD

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
openbsd
exploit available

Summary

A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.

Exploit-Db

descriptionOpenBSD - 'at' Local Root Stack Clash Exploit. CVE-2017-1000373. Local exploit for OpenBSD platform
fileexploits/openbsd/local/42271.c
idEDB-ID:42271
last seen2017-06-29
modified2017-06-28
platformopenbsd
port
published2017-06-28
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/42271/
titleOpenBSD - 'at' Local Root Stack Clash Exploit
typelocal