Use-After-Free Vulnerability in Ledger-CLI by Ledger
CVE-2017-2808

7.5HIGH

Key Information:

Vendor

Ledger

Vendor
CVE Published:
5 September 2017

What is CVE-2017-2808?

A critical flaw exists in the account parsing component of Ledger-CLI version 3.1.1, whereby a specially crafted ledger file can trigger a use-after-free condition. This vulnerability allows an attacker to execute arbitrary code on a user's system by convincing them to load a malicious journal file, thereby compromising system security. Users of Ledger-CLI are urged to exercise caution and to apply security updates to mitigate potential risks.

Affected Version(s)

Ledger CLI Ledger HEAD Ledger 3.1.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.