Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gsoap | Sep 20, 2017 | Jul 19, 2017 |
| Debian | — | Upgrade gsoapUpgrade r-other-x4r | Feb 25, 2019 | Jul 19, 2017 |
| Freebsd | — | Upgrade gsoap | Jul 25, 2017 | Jul 25, 2017 |
| Oracle Solaris | — | Upgrade system/library/security/pkcs11_kms to version 0.5.11-0.175.3.29.0.4.0 on Solaris 11.3 | Feb 22, 2018 | Jul 19, 2017 |
| Suse | — | Upgrade libgsoap-2_8_46Upgrade gsoap-docUpgrade gsoap-develUpgrade libgsoap-2_8_46-debuginfoUpgrade libgsoap-2_8_33Upgrade gsoap-debugsourceUpgrade libgsoap-2_8_33-debuginfoUpgrade gsoap-devel-debuginfo | Jul 26, 2017 | Jul 19, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub