CVE-2017-2808: Ledger-CLI Ledger
High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to load a journal file to trigger this vulnerability.
Affected products
- Ledger-CLI Ledger: version 3.1.1 only
Published 2017-09-05. Last modified 2026-06-17.