8.8
CVE-2017-2812
- EPSS 1.57%
- Veröffentlicht 24.04.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 03:24:12
- CVE-Watchlists
- Unerledigt
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kakadusoftware ≫ Kakadu Sdk Version7.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.57% | 0.722 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
| Cisco Talos | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://www.securityfocus.com/bid/100140
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0309