PT-2017-15554 · Libofx+1 · Libofx+1

Published

2017-09-13

·

Updated

2023-01-28

·

CVE-2017-2816

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibOFX version 0.9.11
Description A buffer overflow issue exists in the tag parsing functionality. This can be triggered by a specially crafted OFX file, causing a write out of bounds and resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to exploit this issue.
Recommendations For LibOFX version 0.9.11, consider avoiding the use of the tag parsing functionality until a fix is available. As a temporary workaround, restrict the processing of OFX files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2017-2816
DLA-1192-1
MGASA-2018-0214
OPENSUSE-SU-2018_2229-1
OPENSUSE-SU-2024:10964-1
SUSE-SU-2018:2045-1
SUSE-SU-2018:2064-1

Affected Products

Libofx
Suse