PoC Index

CVE-2017-1085

HIGH 7.8EPSS 1.8%

In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.

CVSS v3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.85% chance of exploitation in the next 30 days, 78th percentile
Published
2018-09-12
Updated
2024-09-16

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related