CVE-2017-7555

Related Vulnerabilities: CVE-2017-7555  

A vulnerability was discovered in augeas affecting the handling of escaped strings. An attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

A vulnerability was discovered in augeas affecting the handling of escaped strings. An attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

Find out more about CVE-2017-7555 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.8
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (augeas) RHSA-2017:2788 2017-09-21

Affected Packages State

Platform Package State
Red Hat Gluster Storage 3 augeas Will not fix
Red Hat Enterprise Linux 7 rhev-hypervisor Affected
Red Hat Enterprise Linux 6 rhev-hypervisor6 Will not fix
Red Hat Enterprise Linux 6 augeas Fix deferred
OpenStack 6 Installer for RHEL 7 augeas Will not fix

Acknowledgements

This issue was discovered by Han Han (Red Hat).