CVE-2017-10687: High severity centos libssh2 vulnerability
Published Jun 29, 2017
·Updated
In LibSass 3.4.5, there is a heap-based buffer over-read in the function jsonmkstream() in sasscontext.cpp. A crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
LibSass LibSass=3.4.5
Event History
Jun 29, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10687?
CVE-2017-10687 is classified as a high severity vulnerability due to its potential to cause remote denial of service attacks.
2
How do I fix CVE-2017-10687?
To fix CVE-2017-10687, upgrade LibSass to a version later than 3.4.5 that addresses this vulnerability.
3
What is the impact of CVE-2017-10687?
The impact of CVE-2017-10687 includes a heap-based buffer over-read that can lead to a denial of service.
4
What software versions are affected by CVE-2017-10687?
CVE-2017-10687 affects LibSass version 3.4.5.
5
Can CVE-2017-10687 be exploited remotely?
Yes, CVE-2017-10687 can be exploited remotely through crafted input.