First published: Fri Dec 01 2017(Updated: )
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact, as demonstrated by the Plan Editor.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inedo Otter | <=1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17086 is classified as a denial of service vulnerability.
To fix CVE-2017-17086, you should upgrade Inedo Otter to version 1.7.5 or later.
CVE-2017-17086 can cause a crash of the application or potentially other unspecified impacts.
CVE-2017-17086 affects Inedo Otter versions up to and including 1.7.4.
Yes, CVE-2017-17086 can be exploited by remote attackers to cause a denial of service.