5
CVSSv2

CVE-2017-7892

Published: 17/04/2017 Updated: 25/04/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Sandstorm Cap'n Proto prior to 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

capnproto capnproto

Vendor Advisories

Debian Bug report logs - #860960 capnproto: CVE-2017-7892 Package: src:capnproto; Maintainer for src:capnproto is Tom Lee <debian@tomleeco>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 22 Apr 2017 17:45:02 UTC Severity: minor Tags: fixed-upstream, security, upstream Found in version capnproto/0 ...

Github Repositories

Wrangling Untrusted File Formats Safely (Formerly known as Puffs: Parsing Untrusted File Formats Safely) Wuffs is a domain-specific language and library for wrangling untrusted file formats safely Wrangling includes parsing, decoding and encoding Examples of such file formats include images, audio, video, fonts and compressed archives Unlike the C programming language, Wuff

Wrangling Untrusted File Formats Safely (Formerly known as Puffs: Parsing Untrusted File Formats Safely) Wuffs is a domain-specific language and library for wrangling untrusted file formats safely Wrangling includes parsing, decoding and encoding Examples of such file formats include images, audio, video, fonts and compressed archives Unlike the C programming language, Wuff