Remote Code Execution Vulnerability in Ledger 3.1.1

Remote Code Execution Vulnerability in Ledger 3.1.1

CVE-2017-12482 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

The ledger::parse_date_mask_routine function in times.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

Learn more about our Web Application Penetration Testing UK.