← back
CVE-2017-1000373

CVE-2017-1000373

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 13%
from disclosure to weapon9 days
Published on NVDJun 19
1st PoC+9d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.