The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-7458.json"
[
{
"digest": {
"function_hash": "45230076817017922627553868133652437512",
"length": 1336.0
},
"id": "CVE-2017-7458-1c52cc06",
"signature_type": "Function",
"source": "https://github.com/ntop/ntopng/commit/01f47e04fd7c8d54399c9e465f823f0017069f8f",
"target": {
"function": "Lua::setParamsTable",
"file": "src/Lua.cpp"
},
"deprecated": false,
"signature_version": "v1"
},
{
"digest": {
"line_hashes": [
"160324394555210514509448589696142407848",
"328260766068523010549289880788576980191",
"41240477667630977198291149469061115489"
],
"threshold": 0.9
},
"id": "CVE-2017-7458-2347328f",
"signature_type": "Line",
"source": "https://github.com/ntop/ntopng/commit/01f47e04fd7c8d54399c9e465f823f0017069f8f",
"target": {
"file": "src/NetworkInterface.cpp"
},
"deprecated": false,
"signature_version": "v1"
},
{
"digest": {
"line_hashes": [
"106019805976255298140023834735704185255",
"91127995900512789900064732114274950627",
"35191940844274961326047896332125235340",
"168078229102304722862558992609458552291"
],
"threshold": 0.9
},
"id": "CVE-2017-7458-5e24b6ef",
"signature_type": "Line",
"source": "https://github.com/ntop/ntopng/commit/01f47e04fd7c8d54399c9e465f823f0017069f8f",
"target": {
"file": "src/Lua.cpp"
},
"deprecated": false,
"signature_version": "v1"
},
{
"digest": {
"function_hash": "73783438478888607597439922526392775887",
"length": 784.0
},
"id": "CVE-2017-7458-98deda18",
"signature_type": "Function",
"source": "https://github.com/ntop/ntopng/commit/01f47e04fd7c8d54399c9e465f823f0017069f8f",
"target": {
"function": "NetworkInterface::getHost",
"file": "src/NetworkInterface.cpp"
},
"deprecated": false,
"signature_version": "v1"
}
]