CVE-2017-1000253 Detail
Modified
This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided.
Current Description
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Source:
MITRE
Description Last Modified:
10/04/2017
View Analysis Description
Analysis Description
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
Source:
MITRE
Description Last Modified:
10/04/2017
Impact
CVSS v3.0 Severity and Metrics:
Base Score:
7.8 HIGH
Vector:
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
(V3 legend)
Impact Score:
5.9
Exploitability Score:
1.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
CVSS v2.0 Severity and Metrics:
Base Score:
7.2 HIGH
Vector:
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
(V2 legend)
Impact Subscore:
10.0
Exploitability Subscore:
3.9
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (AU):
None
Confidentiality (C):
Complete
Integrity (I):
Complete
Availability (A):
Complete
Additional Information:
Allows unauthorized disclosure of information Allows unauthorized modification Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.
Change History
3 change records found
- show changes
CVE Modified by MITRE -
12/8/2017 9:29:05 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2793 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2794 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2795 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2796 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2797 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2798 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2799 [No Types Assigned] |
CVE Modified by MITRE -
12/7/2017 9:29:00 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2800 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2801 [No Types Assigned] |
| Added |
Reference |
|
https://access.redhat.com/errata/RHSA-2017:2802 [No Types Assigned] |
Initial Analysis -
10/20/2017 11:34:32 AM
| Action |
Type |
Old Value |
New Value |
| Added |
CPE Configuration |
|
Record truncated, showing 500 of 1498 characters.
View Entire Change Record
OR
*cpe:2.3:o:centos:centos:6.0:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.1:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.2:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.3:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.4:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.5:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.6:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.7:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.8:*:*:*:*:*:*:*
*cpe:2.3:o:centos:centos:6.9:*:*:*:*:*:*:*
*cpe:2.3:o:c |
| Added |
CVSS V2 |
|
(AV:L/AC:L/Au:N/C:C/I:C/A:C) |
| Added |
CVSS V3 |
|
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Added |
CWE |
|
CWE-119 |
| Changed |
Reference Type |
http://www.securityfocus.com/bid/101010 No Types Assigned |
http://www.securityfocus.com/bid/101010 Third Party Advisory, VDB Entry |
| Changed |
Reference Type |
http://www.securitytracker.com/id/1039434 No Types Assigned |
http://www.securitytracker.com/id/1039434 Third Party Advisory, VDB Entry |
| Changed |
Reference Type |
https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt No Types Assigned |
https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt Patch, Third Party Advisory |
Quick Info
CVE Dictionary Entry:
CVE-2017-1000253
NVD Published Date:
10/04/2017
NVD Last Modified:
12/08/2017
|