Vulnerability Description
In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flightgear | Flightgear | 2017.2.1 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/flightgear/flightgear/ci/2a5e3d06b2c0d9f831063afe7e726ExploitThird Party Advisory
- https://sourceforge.net/p/flightgear/flightgear/ci/c7a2aef59979af3e9ff22daabb37bExploitThird Party Advisory
- https://sourceforge.net/p/flightgear/flightgear/ci/2a5e3d06b2c0d9f831063afe7e726ExploitThird Party Advisory
- https://sourceforge.net/p/flightgear/flightgear/ci/c7a2aef59979af3e9ff22daabb37bExploitThird Party Advisory
FAQ
What is CVE-2017-13709?
CVE-2017-13709 is a vulnerability with a CVSS score of 7.5 (HIGH). In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.
How severe is CVE-2017-13709?
CVE-2017-13709 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-13709?
Check the references section above for vendor advisories and patch information. Affected products include: Flightgear Flightgear.