RULE(RULE ID:317694)

Rule General Information
Release Date: 2017-07-25
Rule Name: Genivia Gsoap Stack Based Buffer Overflow Vulnerability (CVE-2017-9765)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Network Device, Others
Reference: SecurityFocusBID:99868
Solutions
The vendor has updated advisory on its official website. Please check it for more information.