CVE-2020-25577

In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(8) does not verify that the RDNSS option does not extend past the end of the received packet before processing its contents. While the kernel currently ignores such malformed packets, it passes them to userspace programs. Any programs expecting the kernel to do validation may be vulnerable to an overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*

History

03 Jun 2021, 19:12

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20210423-0001/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20210423-0001/ - Third Party Advisory

23 Apr 2021, 06:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20210423-0001/ -

02 Apr 2021, 15:00

Type Values Removed Values Added
CWE CWE-120
References (MISC) https://security.FreeBSD.org/advisories/FreeBSD-SA-20:32.rtsold.asc - (MISC) https://security.FreeBSD.org/advisories/FreeBSD-SA-20:32.rtsold.asc - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CPE cpe:2.3:o:freebsd:freebsd:12.1:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.1:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.4:p2:*:*:*:*:*:*

29 Mar 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-29 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-25577

Mitre link : CVE-2020-25577

CVE.ORG link : CVE-2020-25577


JSON object : View

Products Affected

freebsd

  • freebsd
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')