Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade augeas | Sep 20, 2017 | Aug 17, 2017 |
| Centos_linux | — | Upgrade augeas-libsUpgrade augeas-debuginfoUpgrade augeasUpgrade augeas-devel | Sep 25, 2017 | Aug 17, 2017 |
| Debian | — | Upgrade augeas | Aug 22, 2017 | Aug 17, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade augeasUpgrade augeas-libs | Nov 30, 2017 | Aug 17, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade augeasUpgrade augeas-libs | Nov 30, 2017 | Aug 17, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 17, 2017 |
| Oracle_linux | — | Upgrade augeasUpgrade augeas-develUpgrade augeas-libs | Sep 27, 2017 | Aug 17, 2017 |
| Redhat_linux | — | Upgrade augeas-debuginfoUpgrade augeas-develUpgrade augeasUpgrade augeas-libsNo solution exists | Oct 4, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade augeas-develUpgrade libaugeas0Upgrade augeasUpgrade augeas-lenses | Mar 10, 2018 | Aug 17, 2017 |
| Ubuntu | — | Upgrade augeas-toolsUpgrade libaugeas0 | Aug 21, 2017 | Aug 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub