PT-2017-15554 · Libofx+1 · Libofx+1
Published
2017-09-13
·
Updated
2023-01-28
·
CVE-2017-2816
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibOFX version 0.9.11
Description
A buffer overflow issue exists in the tag parsing functionality. This can be triggered by a specially crafted OFX file, causing a write out of bounds and resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to exploit this issue.
Recommendations
For LibOFX version 0.9.11, consider avoiding the use of the tag parsing functionality until a fix is available. As a temporary workaround, restrict the processing of OFX files from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libofx
Suse