High severity8.8NVD Advisory· Published Sep 13, 2017· Updated May 13, 2026
CVE-2017-2816
CVE-2017-2816
Description
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
Affected products
3- cpe:2.3:a:libofx_project:libofx:0.9.11:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- LibOFX/LibOfxv5Range: 0.9.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0317nvdExploitTechnical DescriptionThird Party Advisory
- www.securityfocus.com/bid/100828nvdBroken LinkThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2017/11/msg00038.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201908-26nvdThird Party Advisory
News mentions
0No linked articles in our index yet.