PT-2017-14308 · Flexense · Syncbreeze Enterprise

Filipe Xavier Oliveira

·

Publicado

2017-10-31

·

Atualizado

2021-03-29

·

CVE-2017-15950

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flexense SyncBreeze Enterprise version 10.1.16
Description The issue is related to a buffer overflow that can be exploited for arbitrary code execution. This is triggered by providing a long input into the Destination directory field, either within an XML document or through the use of passive mode.
Recommendations For Flexense SyncBreeze Enterprise version 10.1.16, avoid using long inputs in the Destination directory field until a fix is available. As a temporary workaround, consider restricting the length of inputs in this field to prevent potential exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15950

Produtos afetados

Syncbreeze Enterprise