CVE-2020-7455
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts…
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-772
- Affected
- freebsd/freebsd
- Source
- secteam@freebsd.org
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:13.libalias.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20200518-0005/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-661/Third Party Advisory, VDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:13.libalias.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20200518-0005/Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-661/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.