Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-9765

Опубликовано: 20 июл. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.1

Описание

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.8.60-2build1
cosmic

not-affected

2.8.60-2build1
devel

not-affected

2.8.60-2build1
disco

not-affected

2.8.60-2build1
eoan

not-affected

2.8.60-2build1
esm-apps/bionic

not-affected

2.8.60-2build1
esm-apps/focal

not-affected

2.8.60-2build1
esm-apps/jammy

not-affected

2.8.60-2build1
esm-apps/noble

not-affected

2.8.60-2build1

Показывать по

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 8 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

CVSS3: 8.1
debian
больше 8 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2 ...

suse-cvrf
больше 8 лет назад

Recommended update for gsoap

CVSS3: 8.1
github
больше 3 лет назад

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

6.8 Medium

CVSS2

8.1 High

CVSS3