Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-8921
HistoryMay 12, 2017 - 7:29 p.m.

Directory traversal

2017-05-1219:29:00
PRIOn knowledge base
www.prio-n.com
3

7.6 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.3%

In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.

CPENameOperatorVersion
flightgearle2017.2

7.6 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.3%