Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7555

Опубликовано: 17 авг. 2017
Источник: debian

Описание

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
augeasfixed1.8.1-1package

Примечания

  • https://github.com/hercules-team/augeas/pull/480

  • https://bugzilla.redhat.com/show_bug.cgi?id=1478373

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 7.8
redhat
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 9.8
nvd
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

suse-cvrf
больше 7 лет назад

Security update for augeas

suse-cvrf
больше 7 лет назад

Security update for augeas