CVE-2017-2807: Ledger-CLI Ledger
High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.
Affected products
- Ledger-CLI Ledger: version 3.1.1 only
Published 2017-09-05. Last modified 2026-06-17.