CVE-2017-9765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
20/07/2017
Last modified:
20/04/2025

Description

Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:genivia:gsoap:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.7:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.8:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.9:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.10:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.11:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.12:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.13:*:*:*:*:*:*:*
cpe:2.3:a:genivia:gsoap:2.7.14:*:*:*:*:*:*:*