7.8

CVE-2017-14339

Exploit
The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
YadifaYadifa Version <= 2.2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.53% 0.828
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

http://www.debian.org/security/2017/dsa-4001
https://github.com/yadifa/yadifa/blob/v2.2.6/ChangeLog
Third Party Advisory
https://www.tarlogic.com/blog/fuzzing-yadifa-dns/
Third Party Advisory
Exploit
Technical Description