Summary
The FTP packet handler in libalias incorrectly calculates some packet lengths. This may result in disclosing small amounts of memory from the kernel (for the in-kernel NAT implementation) or from the process space for natd (for the userspace implementation).
Credit:
The information has been provided by Vendor
The original article can be found at:https://security.FreeBSD.org/advisories/FreeBSD-SA-20:13.libalias.asc
Details
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).
Vulnerable Systems:
FreeBSD 12.1-STABLE before r360973
FreeBSD 12.1-RELEASE before p5
FreeBSD 11.4-STABLE before r360973
FreeBSD 11.4-BETA1 before p1
FreeBSD 11.3-RELEASE before p9
CVE Information:
Disclosure Timeline:
Published Date:5/13/2020