First published: Wed May 03 2017(Updated: )
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 AppSpider | <=6.14.059 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5240 has been classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2017-5240, you should upgrade Rapid7 AppSpider Pro to version 6.14.060 or later.
CVE-2017-5240 specifically affects the FLAnalyzer.exe component in Rapid7 AppSpider Pro.
CVE-2017-5240 exposes the application to a denial of service attack through a heap-based buffer overflow.
Rapid7 AppSpider Pro versions prior to 6.14.060 are vulnerable to CVE-2017-5240.