Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7555

Опубликовано: 17 авг. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

РелизСтатусПримечание
devel

not-affected

1.8.1-1
esm-infra-legacy/trusty

released

1.2.0-0ubuntu1.3
esm-infra/xenial

released

1.4.0-0ubuntu1.1
precise/esm

DNE

trusty

released

1.2.0-0ubuntu1.3
trusty/esm

released

1.2.0-0ubuntu1.3
upstream

needs-triage

vivid/ubuntu-core

DNE

xenial

released

1.4.0-0ubuntu1.1
zesty

released

1.6.0-0ubuntu3.1

Показывать по

EPSS

Процентиль: 81%
0.01596
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 9.8
nvd
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CVSS3: 9.8
debian
около 8 лет назад

Augeas versions up to and including 1.8.0 are vulnerable to heap-based ...

suse-cvrf
больше 7 лет назад

Security update for augeas

suse-cvrf
больше 7 лет назад

Security update for augeas

EPSS

Процентиль: 81%
0.01596
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3