CVE-2017-1000376 Details
Description
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000376 | CVE | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2020.html | CVE | Third Party Advisory |
| https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | CVE | Mailing ListThird Party Advisory |
| http://www.debian.org/security/2017/dsa-3889 | CVE | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2017-1000376 | [email protected] | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2020.html | [email protected] | Third Party Advisory |
| https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt | [email protected] | Mailing ListThird Party Advisory |
| http://www.debian.org/security/2017/dsa-3889 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat enterprise virtualization server | All versions |
CPE
Remediation
| |
| redhat openshift | 2.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 |
CPE
Remediation
| |
| debian debian linux | 8.0 9.0 |
CPE
Remediation
| |
| libffi project libffi | < 3.2 |
CPE
Remediation
| |
| oracle peopletools | 8.56 8.57 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 22, 2023 | Modified Analysis | [email protected] |
| Jan 15, 2020 | CVE Modified | [email protected] |
| Dec 17, 2019 | CPE Deprecation Remap | [email protected] |
| Apr 26, 2019 | Modified Analysis | [email protected] |
| Apr 22, 2019 | CPE Deprecation Remap | [email protected] |
| Nov 4, 2017 | CVE Modified | [email protected] |
| Jul 5, 2017 | Initial Analysis | [email protected] |
| Jun 29, 2017 | CVE Modified | [email protected] |