CVE-2017-1000376

HIGHCVSS 7/10EPSS 0.50%

Last modified

CVE-2017-1000376 is a high-severity vulnerability rated 7/10 on the CVSS scale. libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. EPSS estimates a 0.50% chance of exploitation in the next 30 days.

Description

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.50%

39.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatEnterprise Virtualization ServerAll versions
RedhatOpenshift2.0
RedhatEnterprise Linux6.0
RedhatEnterprise Linux7.0
DebianDebian Linux8.0
DebianDebian Linux9.0
Libffi ProjectLibffi< 3.2
OraclePeopletools8.56
OraclePeopletools8.57

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-1000376?
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.
How severe is CVE-2017-1000376?
CVE-2017-1000376 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.50% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1000376?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-1000376?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST