BSA-2017-382
21514
13 October 2017
25 August 2017
Closed
Critical
9.4
N/A
CVE-2017-9765
Summary
Security Advisory ID : BSA-2017-382
Component : gSOAP
Revision : 2.0: Interim
Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.
Affected ProductsBrocade is investigating its product lines to determine which products may be affected by this vulnerability and the impact on each affected product.
Products Confirmed Not VulnerableBrocade NetIron OS, Brocade Network OS, Brocade ServerIron ADX, and Brocade SLX-OS are confirmed not affected by this vulnerability.
WorkaroundThere are no workarounds that address this vulnerability.
Revision History
Version | Change | Date |
---|---|---|
1.0 | Initial Publication | August 25, 2017 |
2.0 | Updated to address ADX | October 13, 2017 |