CVE-2017-11757
Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583. The overflow occurs after Server-Client encryption-key exchange. The issue results from an integer underflow that leads to a zero-byte allocation. The _srvLnaConnectMP1 function is affected.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.49% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-191
- Affected
- actian/pervasive psql · actian/zen
- Source
- cve@mitre.org
References
- http://supportservices.actian.com/support-services/security-center#announcementsVendor Advisory
- https://blogs.securiteam.com/index.php/archives/2924Exploit, Third Party Advisory
- https://twitter.com/SecuriTeam_SSD/status/815567538318954496Third Party Advisory
- http://supportservices.actian.com/support-services/security-center#announcementsVendor Advisory
- https://blogs.securiteam.com/index.php/archives/2924Exploit, Third Party Advisory
- https://twitter.com/SecuriTeam_SSD/status/815567538318954496Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.