Vulnerability Details CVE-2017-9831
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.0%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.6
Products affected by CVE-2017-9831
-
cpe:2.3:a:libmtp_project:libmtp:1.1.12