CVE-2017-14731: Medium severity libofx vulnerability
Published Sep 25, 2017
·Updated
ofxprocfile in ofxpreproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an ofxdump call.
Affected Software
1 affected component
Libofx Project Libofx=0.9.12
Remediation
Patch Available
Event History
Sep 25, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What must an attacker do to trigger the crash?
They must cause a vulnerable LibOFX consumer to process a crafted file. The issue can be demonstrated through an ofxdump call and does not require attacker privileges, but it does require user interaction to open or process the file.
2
What is the practical impact of successful exploitation?
Successful exploitation causes a heap-based buffer over-read that can crash the affected application, resulting in denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.
3
Is a fix available?
Yes. A patch is available.