CVE-2017-2254: Input Validation
Published Aug 28, 2017
·Updated
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
Affected Software
21 affected components
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Cybozu Garoon=4.2.3
Cybozu Garoon=4.2.4
Cybozu Garoon=4.2.5
Event History
Aug 28, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2254?
CVE-2017-2254 has been classified as a denial-of-service vulnerability that can significantly impact the availability of the Cybozu Garoon application.
2
How do I fix CVE-2017-2254?
To mitigate CVE-2017-2254, upgrade to a patched version of Cybozu Garoon that is not affected, such as any version beyond 4.2.5.
3
What versions of Cybozu Garoon are affected by CVE-2017-2254?
Cybozu Garoon versions 3.5.0 to 4.2.5 are affected by CVE-2017-2254.
4
What kind of attack does CVE-2017-2254 enable?
CVE-2017-2254 allows an attacker to execute a denial-of-service attack through specially crafted input affecting the application menu.
5
Is there any workaround for CVE-2017-2254 if I cannot upgrade?
There are no known workarounds for CVE-2017-2254, and upgrading is the recommended solution.