Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7555

Опубликовано: 17 авг. 2017
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

A vulnerability was discovered in augeas affecting the handling of escaped strings. An attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6augeasWill not fix
Red Hat Enterprise Linux 7rhev-hypervisorAffected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstalleraugeasWill not fix
Red Hat Enterprise Virtualization 3rhev-hypervisor6Out of support scope
Red Hat Storage 3augeasWill not fix
Red Hat Enterprise Linux 7augeasFixedRHSA-2017:278821.09.2017
Red Hat Enterprise Linux 7.3 Advanced Update SupportaugeasFixedRHSA-2019:240307.08.2019
Red Hat Enterprise Linux 7.3 Telco Extended Update SupportaugeasFixedRHSA-2019:240307.08.2019
Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionsaugeasFixedRHSA-2019:240307.08.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1478373augeas: Improper handling of escaped strings leading to memory corruption

EPSS

Процентиль: 81%
0.01596
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 9.8
nvd
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 9.8
debian
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based ...

suse-cvrf
больше 7 лет назад

Security update for augeas

suse-cvrf
больше 7 лет назад

Security update for augeas

EPSS

Процентиль: 81%
0.01596
Низкий

7.8 High

CVSS3