Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2885

Опубликовано: 10 авг. 2017
Источник: redhat
CVSS3: 7.3
EPSS Средний

Описание

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

A stack-based buffer overflow flaw was discovered within the HTTP processing of libsoup. A remote attacker could exploit this flaw to cause a crash or, potentially, execute arbitrary code by sending a specially crafted HTTP request to a server using the libsoup HTTP server functionality or by tricking a user into connecting to a malicious HTTP server with an application using the libsoup HTTP client functionality.

Отчет

This issue affects the libsoup packages as shipped with Red Hat Enterprise Linux 7. However, these packages have been compiled with additional security mitigation techniques ("stack smashing protection"), which makes exploitation significantly harder. Thus, in most cases an exploitation attempt should be mitigated to a mere crash. However, successful exploitation to execute arbitrary code can't be ruled out entirely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libsoupNot affected
Red Hat Enterprise Linux 6libsoupNot affected
Red Hat Enterprise Linux 7libsoupFixedRHSA-2017:245910.08.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1479281libsoup: Stack based buffer overflow with HTTP Chunked Encoding

EPSS

Процентиль: 94%
0.13197
Средний

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

CVSS3: 9.8
nvd
больше 7 лет назад

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

CVSS3: 9.8
debian
больше 7 лет назад

An exploitable stack based buffer overflow vulnerability exists in the ...

suse-cvrf
больше 8 лет назад

Security update for libsoup

suse-cvrf
больше 8 лет назад

Security update for libsoup

EPSS

Процентиль: 94%
0.13197
Средний

7.3 High

CVSS3