Security Advisory

CVE-2017-2807

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-05 18:00:00
Last updated 2024-09-16 16:42:54
Assigner talos
CVSS score 7.5
State PUBLISHED

Description

An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.