CVE-2017-2807
Gentoo Linux Security Advisory 202004-05
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.
Existe una vulnerabilidad explotable de desbordamiento de búfer en la funcionalidad de análisis sintáctico de etiquetas de Ledger-CLI 3.1.1. Un archivo journal especialmente manipulado podría provocar un desbordamiento inferior de enteros que daría lugar a la ejecución de código. Un atacante puede crear un archivo journal malicioso para provocar esta vulnerabilidad.
Multiple vulnerabilities have been found in ledger, the worst of which could result in the arbitrary execution of code. Versions less than 3.1.2 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2017-09-05 CVE Published
- 2024-09-16 CVE Updated
- 2025-04-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100543 | Third Party Advisory | |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0303 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00031.html | 2022-04-19 | |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00029.html | 2022-04-19 | |
https://security.gentoo.org/glsa/202004-05 | 2022-04-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ledger-cli Search vendor "Ledger-cli" | Ledger Search vendor "Ledger-cli" for product "Ledger" | 3.1.1 Search vendor "Ledger-cli" for product "Ledger" and version "3.1.1" | - |
Affected
|