CVE-2017-9104

Severity
9.8CRITICAL
EPSS
0.7%
top 28.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateMay 24

Description

An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDgnu/adns< 1.5.2
Debianadns< 1.6.0-2+3
NVDopensuse/leap15.1

Also affects: Fedora 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-865c-hm43-j28h: An issue was discovered in adns before 12022-05-24
OSV
CVE-2017-9104: An issue was discovered in adns before 12020-06-18
CVEList
CVE-2017-9104: An issue was discovered in adns before 12020-06-18

📋Vendor Advisories

1
Debian
CVE-2017-9104: adns - An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compres...2017

💬Community

2
Bugzilla
CVE-2017-9104 adns: uncontrolled resource consumption when a compression pointer loop is encountered [fedora-all]2020-06-22
Bugzilla
CVE-2017-9104 adns: uncontrolled resource consumption when a compression pointer loop is encountered2020-06-22