Denial of Service Vulnerability in Ledger by Ledger CLI
CVE-2017-12482
7.8HIGH
What is CVE-2017-12482?
The ledger::parse_date_mask_routine function in times.cc of Ledger version 3.1.1 has a vulnerability that could allow remote attackers to create specially crafted files, leading to a denial of service by causing a stack-based buffer overflow and crashing the application. This vulnerability highlights the importance of robust input validation to mitigate such risks.
