Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
BID:100543
CVE-2017-2807 |Info
Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
| Bugtraq ID: | 100543 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-2807 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2017 12:00AM |
| Updated: | Aug 30 2017 12:00AM |
| Credit: | Cory Duplantis from Cisco Talos. |
| Vulnerable: |
ledger Ledger CLI 3.1.1 |
| Not Vulnerable: | |
Discussion
Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
Ledger CLI is prone to a remote code-execution vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Ledger CLI 3.1.1 is vulnerable; other versions may also be affected.
Ledger CLI is prone to a remote code-execution vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Ledger CLI 3.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
Ledger CLI CVE-2017-2807 Remote Code Execution Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.