PT-2017-15554 · Libofx+1 · Libofx+1

CVE-2017-2816

·

Published

2017-09-13

·

Updated

2023-01-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibOFX version 0.9.11
Description A buffer overflow issue exists in the tag parsing functionality. This can be triggered by a specially crafted OFX file, causing a write out of bounds and resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to exploit this issue.
Recommendations For LibOFX version 0.9.11, consider avoiding the use of the tag parsing functionality until a fix is available. As a temporary workaround, restrict the processing of OFX files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2816
DLA-1192-1
MGASA-2018-0214
OPENSUSE-SU-2018_2229-1
OPENSUSE-SU-2024:10964-1
SUSE-SU-2018:2045-1
SUSE-SU-2018:2064-1

Affected Products

Libofx
Suse