CVE-2017-3111
published 2017-12-09CVE-2017-3111: An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
6.79%
93.3th percentile
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-13741 liblouis: Use-after-free in the function compileBrailleIndicator()
bugzilla·2017-09-06·CVSS 6.5
CVE-2017-13741 [MEDIUM] CVE-2017-13741 liblouis: Use-after-free in the function compileBrailleIndicator()
CVE-2017-13741 liblouis: Use-after-free in the function compileBrailleIndicator()
There is a use-after-free in the function compileBrailleIndicator() in compileTranslationTable.c in Liblouis 3.2.0 that will lead to a denial of service attack.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484332
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
Bugzilla
CVE-2017-13738 liblouis: Illegal address access in the _lou_getALine function
bugzilla·2017-09-06·CVSS 8.8
CVE-2017-13738 [HIGH] CVE-2017-13738 liblouis: Illegal address access in the _lou_getALine function
CVE-2017-13738 liblouis: Illegal address access in the _lou_getALine function
There is an illegal address access in the _lou_getALine function in compileTranslationTable.c:346 in Liblouis 3.2.0.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484297
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
Bugzilla
CVE-2017-13740 liblouis: Stack-buffer overflow in the parseChars() function
bugzilla·2017-09-06·CVSS 8.8
CVE-2017-13740 [HIGH] CVE-2017-13740 liblouis: Stack-buffer overflow in the parseChars() function
CVE-2017-13740 liblouis: Stack-buffer overflow in the parseChars() function
There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function parseChars() in compileTranslationTable.c, that will lead to denial of service or possibly unspecified other impact.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484306
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
Bugzilla
CVE-2017-13742 liblouis: Stack-buffer overflow in the function includeFile()
bugzilla·2017-09-06·CVSS 6.5
CVE-2017-13742 [MEDIUM] CVE-2017-13742 liblouis: Stack-buffer overflow in the function includeFile()
CVE-2017-13742 liblouis: Stack-buffer overflow in the function includeFile()
There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function includeFile() in compileTranslationTable.c, that will lead to a denial of service attack.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484334
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
Bugzilla
CVE-2017-13743 liblouis: Buffer overflow in the function _lou_showString()
bugzilla·2017-09-06·CVSS 6.5
CVE-2017-13743 [MEDIUM] CVE-2017-13743 liblouis: Buffer overflow in the function _lou_showString()
CVE-2017-13743 liblouis: Buffer overflow in the function _lou_showString()
There is a buffer overflow in Liblouis 3.2.0, triggered in the function _lou_showString() in utils.c, that will lead to a denial of service attack.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484335
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
Bugzilla
CVE-2017-13744 liblouis: Illegal address access in the _lou_getALine() function
bugzilla·2017-09-06·CVSS 6.5
CVE-2017-13744 [MEDIUM] CVE-2017-13744 liblouis: Illegal address access in the _lou_getALine() function
CVE-2017-13744 liblouis: Illegal address access in the _lou_getALine() function
There is an illegal address access in the function _lou_getALine() in compileTranslationTable.c:343 in Liblouis 3.2.0.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1484338
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1488944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:3111 https://access.redhat.com/errata/RHSA-2017:3111
http://www.securityfocus.com/bid/101843http://www.securitytracker.com/id/1039800https://helpx.adobe.com/security/products/experience-manager/apsb17-41.htmlhttp://www.securityfocus.com/bid/101843http://www.securitytracker.com/id/1039800https://helpx.adobe.com/security/products/experience-manager/apsb17-41.html
2017-12-09
Published