CVE-2017-2808
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to load a journal file to trigger this vulnerability.
Existe una vulnerabilidad explotable de uso de memoria previamente liberada (use-after-free) en el componente de análisis sintáctico de cuentas de Ledger-CLI 3.1.1. Un archivo ledger especialmente manipulado puede provocar una vulnerabilidad de uso de memoria previamente liberada que daría lugar a la ejecución de código arbitrario. Un atacante puede convencer a un usuario para que cargue un archivo journal para provocar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2017-09-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100546 | Third Party Advisory | |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0304 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00031.html | 2022-04-19 | |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00029.html | 2022-04-19 | |
https://security.gentoo.org/glsa/202004-05 | 2022-04-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ledger-cli Search vendor "Ledger-cli" | Ledger Search vendor "Ledger-cli" for product "Ledger" | 3.1.1 Search vendor "Ledger-cli" for product "Ledger" and version "3.1.1" | - |
Affected
|