CVE-2017-5240: Buffer Overflow
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5240?
CVE-2017-5240 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2017-5240?
To fix CVE-2017-5240, you should upgrade Rapid7 AppSpider Pro to version 6.14.060 or later.
What component is affected by CVE-2017-5240?
CVE-2017-5240 specifically affects the FLAnalyzer.exe component in Rapid7 AppSpider Pro.
What type of attack does CVE-2017-5240 expose the application to?
CVE-2017-5240 exposes the application to a denial of service attack through a heap-based buffer overflow.
Which versions of Rapid7 AppSpider Pro are vulnerable to CVE-2017-5240?
Rapid7 AppSpider Pro versions prior to 6.14.060 are vulnerable to CVE-2017-5240.