Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the large document would be blocked by many common web-server configurations on general-purpose computers.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-20T00:00:00

Updated: 2024-08-05T17:18:01.972Z

Reserved: 2017-06-21T00:00:00

Link: CVE-2017-9765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-07-20T00:29:00.463

Modified: 2023-11-07T02:50:51.873

Link: CVE-2017-9765

cve-icon Redhat

No data.