CVE-2017-6952 (NVD)

2017-03-16

Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.

Products Capstone
Type Integer Overflow or Wraparound (CWE-190)
First patch https://github.com/aquynh/capstone/commit/6fe86eef621b9849f51a5e1e5d73258a93440403
Relevant file/s ./windows/winkernel_mm.c (modified, +11, -2)
Links http://www.securityfocus.com/bid/97323

capstone - Tree: 6fe86eef62

(? files)

Filter Settings
Files
Navigation
Patch data:

(on by default)


Patched area: