[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3889-1 libffi -- libffi

ID: oval:org.secpod.oval:def:602948Date: (C)2017-06-22   (M)2023-09-30
Class: PATCHFamily: unix




libffi, a library used to call code written in one language from code written in a different language, was enforcing an executable stack on the i386 architecture. While this might not be considered a vulnerability by itself, this could be leveraged when exploiting other vulnerabilities, like for example the stack clash class of vulnerabilities discovered by Qualys Research Labs. For the full details, please refer to their advisory published at: https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

Platform:
Debian 8.x
Debian 9.x
Product:
libffi
libffi6
Reference:
DSA-3889-1
CVE-2017-1000376
CVE    1
CVE-2017-1000376
CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.x
cpe:/a:sourceware:libffi6
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies