Security Advisory

CVE-2017-5240

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-05-03 16:00:00
Last updated 2024-08-05 14:55:35
Assigner rapid7
CVSS score not scored
State PUBLISHED

Description

Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash.