CVE-2017-8891: Medium severity dropbox vulnerability
Published May 10, 2017
·Updated
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
Affected Software
1 affected component
Dropbox Lepton=1.2.1
Remediation
Patch Available
Patch Available
Event History
May 10, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8891?
CVE-2017-8891 is classified as a moderate severity vulnerability due to potential denial of service through application crashes.
2
How do I fix CVE-2017-8891?
To fix CVE-2017-8891, you should update to a later version of Dropbox Lepton that addresses the threading issue.
3
What type of vulnerability is CVE-2017-8891?
CVE-2017-8891 is a denial of service vulnerability affecting Dropbox Lepton due to mishandling of malformed lepton files.
4
Which version of Dropbox Lepton is affected by CVE-2017-8891?
CVE-2017-8891 specifically affects Dropbox Lepton version 1.2.1.
5
What happens if CVE-2017-8891 is exploited?
If CVE-2017-8891 is exploited, it can lead to application crashes or segmentation faults, resulting in denial of service.