CVE-2017-20227: Critical Vulnerability in Multiple Products
Summary
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and exec
Threat Analysis
**Vulnerability ID:** CVE-2017-20227 **CVSS Score:** 9.8 (CRITICAL)
**Description:** JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and exec
**Recommended Actions:** - Review vendor security advisories - Plan patch deployment according to risk assessment - Implement compensating controls where applicable