Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9831

Опубликовано: 24 июн. 2017
Источник: debian
EPSS Низкий

Описание

An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmtpfixed1.1.13-1package

Примечания

  • https://sourceforge.net/p/libmtp/mailman/message/35735992/

  • https://sourceforge.net/p/libmtp/code/ci/aa7d91a789873a9d86969028e57f888a1241c085/

  • reduced patchset: https://lists.debian.org/87lgnzvjvb.fsf@curie.anarc.at

EPSS

Процентиль: 46%
0.00232
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 8 лет назад

An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.

CVSS3: 3.1
redhat
почти 9 лет назад

An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.

CVSS3: 6.8
nvd
больше 8 лет назад

An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.

CVSS3: 6.8
github
больше 3 лет назад

An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.

EPSS

Процентиль: 46%
0.00232
Низкий