CVE-2017-2693
published 2017-11-22CVE-2017-2693: ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.05%
60.3th percentile
ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a path traversal vulnerability. An attacker may exploit it to decompress malicious files into a target path.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | g8_firmware | <= rio-al00c00b220 | — |
| huawei | g8_firmware | <= rio-cl00c92b220 | — |
| huawei | g8_firmware | <= rio-tl00c01b220 | — |
| huawei | g8_firmware | <= rio-ul00c00b220 | — |
| huawei | honor_6_firmware | <= h60-l04c10b523 | — |
| huawei | honor_6_firmware | <= h60-l04c185b523 | — |
| huawei | honor_6_firmware | <= h60-l04c636b527 | — |
| huawei | honor_6_firmware | <= h60-l04c900b530 | — |
| huawei | honor_7_firmware | <= plk-al10c00b220 | — |
| huawei | honor_7_firmware | <= plk-al10c92b220 | — |
| huawei | honor_7_firmware | <= plk-cl00c92b220 | — |
| huawei | honor_7_firmware | <= plk-l01c10b140 | — |
| huawei | honor_7_firmware | <= plk-l01c432b187 | — |
| huawei | honor_7_firmware | <= plk-l01c432b190 | — |
| huawei | honor_7_firmware | <= plk-l01c636b130 | — |
| huawei | honor_7_firmware | <= plk-tl00c01b220 | — |
| huawei | honor_7_firmware | <= plk-tl01hc01b220 | — |
| huawei | honor_7_firmware | <= plk-ul00c17b220 | — |
| huawei | mate_7_firmware | <= mt7-l09c605b325 | — |
| huawei | mate_7_firmware | <= mt7-l09c900b339 | — |
| huawei | mate_7_firmware | <= mt7-tl10c900b339 | — |
| huawei | mate_s_firmware | <= crr-cl00c92b172 | — |
| huawei | mate_s_firmware | <= crr-l09c432b180 | — |
| huawei | mate_s_firmware | <= crr-tl00c01b172 | — |
| huawei | mate_s_firmware | <= crr-ul00c00b172 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
bugzilla·2017-05-23·CVSS 7.5
CVE-2017-5637 [HIGH] CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
Two four letter word commands “wchp/wchc” are CPU intensive and could cause spike of CPU utilization on ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.
Upstream issue:
https://issues.apache.org/jira/browse/ZOOKEEPER-2693
References:
https://vulners.com/exploitdb/EDB-ID:41277
Discussion:
Created zookeeper tracking bugs for this issue:
Affects: fedora-all [bug 1454809]
---
taking
---
For fuse the recommended security practice to mitigate this issue is to deploy and operate zookeeper in a secured network where essentially the affected port are protected by the firewall. Additionally it should be assumed that only admin has access to the affected po
Bugzilla
CVE-2017-9147 libtiff: Out of bounds read in _TIFFVGetField
bugzilla·2017-05-23·CVSS 6.5
CVE-2017-9147 [MEDIUM] CVE-2017-9147 libtiff: Out of bounds read in _TIFFVGetField
CVE-2017-9147 libtiff: Out of bounds read in _TIFFVGetField
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2693
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1454663]
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1454664]
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1454661]
Affects: fedora-all [bug 1454658]
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1454659]
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1454662]
Created openjpeg track
2017-11-22
Published