CVE-2017-2816
published 2017-09-13CVE-2017-2816: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.39%
82.3th percentile
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libofx | < libofx 1:0.9.11-4 (bookworm) | libofx 1:0.9.11-4 (bookworm) |
| libofx | libofx | — | — |
| libofx_project | libofx | — | — |
| libofx_project | libofx | >= 0 < 1:0.9.11-4 | 1:0.9.11-4 |
| libofx_project | libofx | >= 0 < 1:0.9.11-4 | 1:0.9.11-4 |
| libofx_project | libofx | >= 0 < 1:0.9.11-4 | 1:0.9.11-4 |
| libofx_project | libofx | >= 0 < 1:0.9.11-4 | 1:0.9.11-4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-2816: libofx - An exploitable buffer overflow vulnerability exists in the tag parsing functiona...
vendor_debian·2017·CVSS 8.8
CVE-2017-2816 [HIGH] CVE-2017-2816: libofx - An exploitable buffer overflow vulnerability exists in the tag parsing functiona...
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1:0.9.11-4)
bullseye: resolved (fixed in 1:0.9.11-4)
forky: resolved (fixed in 1:0.9.11-4)
sid: resolved (fixed in 1:0.9.11-4)
trixie: resolved (fixed in 1:0.9.11-4)
GHSA
GHSA-3w43-mhj6-r4fj: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0
ghsa_unreviewed·2022-05-13
CVE-2017-2816 [HIGH] CWE-119 GHSA-3w43-mhj6-r4fj: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
OSV
CVE-2017-2816: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0
osv·2017-09-13·CVSS 8.8
CVE-2017-2816 [HIGH] CVE-2017-2816: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17795 libtiff: Heap-based buffer overflow in tiff2pdf.c:t2p_write_pdf()
bugzilla·2018-10-02·CVSS 8.8
CVE-2018-17795 [HIGH] CVE-2018-17795 libtiff: Heap-based buffer overflow in tiff2pdf.c:t2p_write_pdf()
CVE-2018-17795 libtiff: Heap-based buffer overflow in tiff2pdf.c:t2p_write_pdf()
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.
Upstream Bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2816
Discussion:
Not reproducible on f28 with libtiff-tools-4.0.9-10.fc28.x86_64.
---
Unable to reproduce on any RHEL* packages.
Bugzilla
CVE-2017-2816 libofx: Stack-based buffer over-write in sanitize_proprietary_tags function in lib/ofx_preproc.cpp
bugzilla·2017-09-15·CVSS 8.8
CVE-2017-2816 [HIGH] CVE-2017-2816 libofx: Stack-based buffer over-write in sanitize_proprietary_tags function in lib/ofx_preproc.cpp
CVE-2017-2816 libofx: Stack-based buffer over-write in sanitize_proprietary_tags function in lib/ofx_preproc.cpp
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
Upstream bug:
https://github.com/libofx/libofx/issues/9
References:
https://bugzilla.novell.com/show_bug.cgi?id=1058673
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0317
Discussion:
Created libofx tracking bugs for this issue:
Affects: epel-all [bug 1492202]
Affects: fedora-all [bug 1492203]
---
This CVE Bugzilla entry is for community support informational purposes
Bugzilla
CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [epel-all]
bugzilla·2017-09-15·CVSS 6.5
CVE-2017-14731 [MEDIUM] CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [epel-all]
CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [fedora-all]
bugzilla·2017-09-15·CVSS 6.5
CVE-2017-14731 [MEDIUM] CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [fedora-all]
CVE-2017-14731 CVE-2017-2816 CVE-2017-2920 libofx: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Talos
Vulnerability Spotlight: LibOFX Tag Parsing Code Execution Vulnerability
blogs_talos·2017-09-13·CVSS 8.8
[HIGH] Vulnerability Spotlight: LibOFX Tag Parsing Code Execution Vulnerability
This vulnerability was discovered by Cory Duplantis of Talos
Update 9/20/2017: A patch is now available to fix this issue.
### OverviewLibOFX is an open source implementation of OFX (Open Financial Exchange) an open format used by financial institutions to share financial data with clients. As an implementation of a complex standard, this library is used by financial software such as GnuCash. Talos has discovered an exploitable buffer overflow in the implementation: a specially crafted OFX file can cause a write out of bounds resulting in code execution. This vulnerability is not currently patched and Talos has not received a response from the developers within the period specified by theVendor Vulnerability Reporting and Disclosure Policy.
### TALOS-2017-0317 (CVE-2017-2816) - LibOFX T
http://www.securityfocus.com/bid/100828https://lists.debian.org/debian-lts-announce/2017/11/msg00038.htmlhttps://security.gentoo.org/glsa/201908-26https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0317http://www.securityfocus.com/bid/100828https://lists.debian.org/debian-lts-announce/2017/11/msg00038.htmlhttps://security.gentoo.org/glsa/201908-26https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0317
2017-09-13
Published