Buffer Overflow in Ledger-CLI Tag Parsing Functionality
CVE-2017-2807

7.5HIGH

Key Information:

Vendor

Ledger

Vendor
CVE Published:
5 September 2017

What is CVE-2017-2807?

A buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI version 3.1.1. An attacker can exploit this flaw by crafting a malicious journal file that triggers an integer underflow, leading to unauthorized code execution. This poses a significant risk, as it could allow an attacker to execute arbitrary code on the affected system.

Affected Version(s)

Ledger CLI 3.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.