CVE-2017-11757

CRITICAL

Actian Pervasive PSQL v12.10-Zen v13 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583. The overflow occurs after Server-Client encryption-key exchange. The issue results from an integer underflow that leads to a zero-byte allocation. The _srvLnaConnectMP1 function is affected.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://twitter.com/SecuriTeam_SSD/status/815567538318954496
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/2924

Scores

CVSS v3 9.8
EPSS 0.0249
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-191
Status published
Products (2)
actian/pervasive_psql 12.10
actian/zen 13.0
Published Jul 31, 2017
Tracked Since Feb 18, 2026