« Volver al listado

CVE-2022-23093

Estado: AnalizadaMedia (6.5)—💥 PoC

ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a "quoted packet," which represents the packet that generated an ICMP error. The quoted packet again has an IP header and an ICMP header.

The pr_pack() copies received IP and ICMP headers into stack buffers for further processing. In so doing, it fails to take into account the possible presence of IP option headers following the IP header in either the response or the quoted packet. When IP options are present, pr_pack() overflows the destination buffer by up to 40 bytes.

Leer descripción completaMostrar menos

The memory safety bugs described above can be triggered by a remote host, causing the ping program to crash.

The ping process runs in a capability mode sandbox on all affected versions of FreeBSD and is thus very constrained in how it can interact with the rest of the system at the point where the bug can occur.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23093",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-23093",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-14T21:25:53.167040Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "FreeBSD",
          "modules": [
            "ping"
          ],
          "product": "FreeBSD",
          "versions": [
            {
              "status": "affected",
              "version": "13.1-RELEASE",
              "lessThan": "p5",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "12.4-RC2",
              "lessThan": "p2",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "12.3-RELEASE",
              "lessThan": "p10",
              "versionType": "release"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-15T06:15:45.240",
  "references": [
    {
      "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:15.ping.asc",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:15.ping.asc",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ping reads raw IP packets from the network to process responses in the pr_pack() function.  As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a \"quoted packet,\" which represents the packet that generated an ICMP error.  The quoted packet again has an IP header and an ICMP header.\n\nThe pr_pack() copies received IP and ICMP headers into stack buffers for further processing.  In so doing, it fails to take into account the possible presence of IP option headers following the IP header in either the response or the quoted packet.  When IP options are present, pr_pack() overflows the destination buffer by up to 40 bytes.\n\nThe memory safety bugs described above can be triggered by a remote host, causing the ping program to crash.\n\nThe ping process runs in a capability mode sandbox on all affected versions of FreeBSD and is thus very constrained in how it can interact with the rest of the system at the point where the bug can occur."
    },
    {
      "lang": "es",
      "value": "ping lee paquetes IP sin procesar de la red para procesar las respuestas en la función pr_pack(). Como parte del procesamiento de una respuesta de ping, se debe reconstruir el encabezado IP, el encabezado ICMP y, si está presente, un \"paquete citado\", que representa el paquete que generó un error ICMP. El paquete citado nuevamente tiene un encabezado IP y un encabezado ICMP. pr_pack() copia los encabezados IP e ICMP recibidos en búferes de pila para su posterior procesamiento. Al hacerlo, no tiene en cuenta la posible presencia de encabezados de opciones de IP después del encabezado de IP, ya sea en la respuesta o en el paquete citado. Cuando las opciones de IP están presentes, pr_pack() desborda el búfer de destino hasta en 40 bytes. Los errores de seguridad de la memoria descritos anteriormente pueden ser desencadenados por un host remoto, lo que provoca que el programa ping falle. El proceso de ping se ejecuta en un modo sandbox de capacidad en todas las versiones afectadas de FreeBSD y, por lo tanto, está muy limitado en cuanto a cómo puede interactuar con el resto del sistema en el punto donde puede ocurrir el error."
    }
  ],
  "lastModified": "2026-06-17T04:29:29.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E231B24D-5CA9-4107-A819-57EE116AD644"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B6DCD8A-331E-419F-9253-C4D35C1DF54B"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4578E06C-16C6-435E-9E51-91CB02602355"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71FA1F6C-7E53-40F8-B9E1-5FD28D5DAADA"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EC87BCE-17F0-479B-84DC-516C24FBD396"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "620C23ED-400C-438C-8427-94437F12EDAF"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEE99CB2-0B1E-4FAB-A7FB-C73E3131B0D8"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "987270DD-4E16-4336-8F38-7C1A6C881B7D"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A057889D-8EB9-4C37-9381-96011F8498A4"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21656E91-D625-45D7-B8A0-9E0DEFB393A2"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA821886-B26B-47A6-ABC9-B8F70CE0ACFB"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66364EA4-83B1-4597-8C18-D5633B361A9C"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF9292DD-EFB1-4B50-A941-7485D901489F"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFB18F55-4F5C-4166-9A7E-6F6617179A90"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66E1C269-841F-489A-9A0A-5D145B417E0A"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECF1B567-F764-45F5-A793-BEA93720F952"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAFE3F33-2C57-4B52-B658-82572607BD8C"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B536EE52-ED49-4A85-BC9D-A27828D5A961"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secteam@freebsd.org"
}