CVE-2017-7555 PUBLISHED

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

EPSS 1.24% · 79.1th percentile

Risk Scores

EPSS Score
1.24%
79.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSaugeas0, 1.3.0-0ubuntu1, 1.3.0-0ubuntu2
Ubuntu:14.04:LTSaugeas1.2.0-0ubuntu1, 0, 1.2.0-0ubuntu1.2

Timeline

References

Open in Interactive Console →