CVE-2017-20229: MAWK 1.3.3-17 Stack-Based Buffer Overflow
MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20229?
CVE-2017-20229 is considered a high-severity vulnerability due to its potential to execute arbitrary code.
How do I fix CVE-2017-20229?
To fix CVE-2017-20229, upgrade MAWK to version 1.3.3-18 or later, which addresses the buffer overflow issue.
What types of software are affected by CVE-2017-20229?
CVE-2017-20229 affects MAWK versions up to and including 1.3.3-17.
What are the potential impacts of exploiting CVE-2017-20229?
Exploiting CVE-2017-20229 could allow attackers to run arbitrary code, leading to data breaches or system compromise.
Is there a workaround for CVE-2017-20229 if I cannot upgrade?
There are no known workarounds for CVE-2017-20229, so upgrading is the recommended approach.