CVE-2017-7467

A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could potentially use this flaw to crash minicom, or execute arbitrary code in the context of the minicom process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minicom_project:minicom:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:31

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 7.0
References () http://www.openwall.com/lists/oss-security/2017/04/18/5 - Exploit, Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2017/04/18/5 - Exploit, Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/97966 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/97966 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7467 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7467 - Issue Tracking
References () https://security.gentoo.org/glsa/201706-13 - Third Party Advisory () https://security.gentoo.org/glsa/201706-13 - Third Party Advisory

Information

Published : 2018-07-11 13:29

Updated : 2024-11-21 03:31


NVD link : CVE-2017-7467

Mitre link : CVE-2017-7467

CVE.ORG link : CVE-2017-7467


JSON object : View

Products Affected

minicom_project

  • minicom
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer