Use-After-Free Vulnerability in Ledger-CLI by Ledger
CVE-2017-2808
7.5HIGH
What is CVE-2017-2808?
A critical flaw exists in the account parsing component of Ledger-CLI version 3.1.1, whereby a specially crafted ledger file can trigger a use-after-free condition. This vulnerability allows an attacker to execute arbitrary code on a user's system by convincing them to load a malicious journal file, thereby compromising system security. Users of Ledger-CLI are urged to exercise caution and to apply security updates to mitigate potential risks.
Affected Version(s)
Ledger CLI Ledger HEAD Ledger 3.1.
