Skip to content

Account directive use-after-free vulnerability with deferred postings (TALOS-2017-0304, CVE-2017-2808) #1723

@tbm

Description

@tbm

Cory Duplantis and another member of Cisco Talos discovered and described an issue with ledger:

An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to load a journal file to trigger this vulnerability.

CVE-2017-2808 was assigned.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions