QID 377845
Date Published: 2023-01-02
QID 377845: Free Berkeley Software Distribution (FreeBSD) Buffer Overflow Vulnerability (FreeBSD-SA-22:15)
FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms.
CVE-2022-23093: The issue is a buffer overflow vulnerability affecting the "pr_pack()" function in ping(8).
Affected Versions:
FreeBSD versions prior to 12.3-RELEASE-p10
FreeBSD versions prior to 12.4-RC2-p2
FreeBSD versions prior to 12.4-STABLE
FreeBSD versions prior to 13.1-STABLE
FreeBSD versions prior to 13.1-RELEASE-p5
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FreeBSD OS
Successful exploitation of this vulnerability may allow an attacker to cause a stack overflow, which could lead to a crash or trigger remote code execution in ping.
Solution
Vendor has released patch to address this issue. Please refer to advisory for FreeBSD-SA-22:15 for further updates.Workaround:
Please refer vendor advisory FreeBSD-SA-22:15 for patch details.
Please refer vendor advisory FreeBSD-SA-22:15 for patch details.
Vendor References
- FreeBSD-SA-22:15 -
www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc
CVEs related to QID 377845
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FreeBSD-SA-22:15 |
|