Back
CVE-2017-14648
CRITICAL
A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.
Published: Sep 21, 2017
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| bladeenc | bladeenc | 0.94.2 |
GitHub Security Advisory GHSA-5h2c-vg38-fcwr
A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc...
References (4)
- https://blogs.gentoo.org/ago/2017/09/19/bladeenc-global-buffer-overflow-in-iteration_loop-loop-c/ Third Party Advisory
- https://security.gentoo.org/glsa/202107-18 Third Party Advisory
- https://blogs.gentoo.org/ago/2017/09/19/bladeenc-global-buffer-overflow-in-iteration_loop-loop-c/ Third Party Advisory
- https://security.gentoo.org/glsa/202107-18 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
3.41%
Top 12% most likely to be exploited
Threat Score
40.2 / 100
Data Sources
NVD
EPSS
GitHub