CVE-2017-9430
CRITICAL 9.8EPSS 11.3%
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.
- CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 11.32% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2017-06-05
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- homjxi0e/CVE-2017-94300★ · 2017-06-08
- migraine-sudo/Exploit-to-DnsTracerv1.91★ · 2019-01-25