cbcvebase.
CVE-2017-9103
published 2020-06-18

CVE-2017-9103: An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.05%
79.0th percentile
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its memory, causing it to allocate lots of memory, or perhaps overrunning a buffer. This is only possible with applications which make non-raw queries for SOA or RP records.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianadns< adns 1.6.0-2 (bookworm)adns 1.6.0-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnuadns< 1.5.21.5.2
gnuadns>= 0 < 1.6.0-21.6.0-2
gnuadns>= 0 < 1.6.0-21.6.0-2
gnuadns>= 0 < 1.6.0-21.6.0-2
gnuadns>= 0 < 1.6.0-21.6.0-2
opensuseleap

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.