7.5

CVE-2017-9454

Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ResiprocateResiprocate Version <= 1.10.2
ResiprocateResiprocate Version1.11.0 Updatealpha1
ResiprocateResiprocate Version1.11.0 Updatealpha10
ResiprocateResiprocate Version1.11.0 Updatealpha11
ResiprocateResiprocate Version1.11.0 Updatealpha2
ResiprocateResiprocate Version1.11.0 Updatealpha3
ResiprocateResiprocate Version1.11.0 Updatealpha4
ResiprocateResiprocate Version1.11.0 Updatealpha5
ResiprocateResiprocate Version1.11.0 Updatealpha6
ResiprocateResiprocate Version1.11.0 Updatealpha7
ResiprocateResiprocate Version1.11.0 Updatealpha8
ResiprocateResiprocate Version1.11.0 Updatealpha9
ResiprocateResiprocate Version1.11.0 Updatebeta1
ResiprocateResiprocate Version1.11.0 Updatebeta2
ResiprocateResiprocate Version1.11.0 Updatebeta3
ResiprocateResiprocate Version1.11.0 Updatebeta4
ResiprocateResiprocate Version1.11.0 Updatebeta5
ResiprocateResiprocate Version1.12.0 Updatealpha1
ResiprocateResiprocate Version1.12.0 Updatebeta1
ResiprocateResiprocate Version1.12.0 Updatebeta2
ResiprocateResiprocate Version1.12.0 Updatebeta3
ResiprocateResiprocate Version1.12.0 Updatebeta4
ResiprocateResiprocate Version1.12.0 Updatebeta5
ResiprocateResiprocate Version1.12.0 Updatebeta6
ResiprocateResiprocate Version1.12.0 Updatebeta7
ResiprocateResiprocate Version1.12.0 Updatebeta8
ResiprocateResiprocate Version1.12.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.