CVE-2017-9103

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-9103
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9103.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-9103
Related
Published
2020-06-18T15:15:10Z
Modified
2024-06-30T12:00:03Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in adns before 1.5.2. papmailbox822 does not properly check st from adnsfindlabelnext. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its memory, causing it to allocate lots of memory, or perhaps overrunning a buffer. This is only possible with applications which make non-raw queries for SOA or RP records.

References

Affected packages

Debian:11 / adns

Package

Name
adns
Purl
pkg:deb/debian/adns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / adns

Package

Name
adns
Purl
pkg:deb/debian/adns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / adns

Package

Name
adns
Purl
pkg:deb/debian/adns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}