243 lines
8.9 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2017-9454",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-08-18T14:29:00.843",
"lastModified": "2019-12-11T22:14:59.490",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response."
},
{
"lang": "es",
"value": "Un desbordamiento de b\u00fafer en la funci\u00f3n ares_parse_a_reply en la biblioteca embebida ares en ReSIProcate en versiones anteriores a la 1.12.0 permite que atacantes remotos provoquen una denegaci\u00f3n de servicio (lectura fuera de l\u00edmites) mediante una respuesta DNS manipulada."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.10.2",
"matchCriteriaId": "D7A9B784-2E65-4DD9-A2BF-37E9423059E9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha1:*:*:*:*:*:*",
"matchCriteriaId": "EBC4049D-A7EE-4E51-82F1-3431B4571C55"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha10:*:*:*:*:*:*",
"matchCriteriaId": "2A32D09D-AFFE-407D-908F-8191D2973C27"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha11:*:*:*:*:*:*",
"matchCriteriaId": "3885433A-D1DE-4970-84AF-A7D6DFAF1B57"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha2:*:*:*:*:*:*",
"matchCriteriaId": "7A6DE94C-6DCB-4668-A326-9E001283C822"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha3:*:*:*:*:*:*",
"matchCriteriaId": "888FA5FD-51E9-4185-ADA1-D668997EB4D8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha4:*:*:*:*:*:*",
"matchCriteriaId": "4402C7AC-9011-4D24-A480-4345E53CCDB1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha5:*:*:*:*:*:*",
"matchCriteriaId": "887E4C3A-421B-45FA-B15A-B28C5441690D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha6:*:*:*:*:*:*",
"matchCriteriaId": "3DF27A62-D822-4EC6-B9B0-8B649E4D1945"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha7:*:*:*:*:*:*",
"matchCriteriaId": "A56BD5AA-5147-46E7-8A9C-D7659910F47E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha8:*:*:*:*:*:*",
"matchCriteriaId": "2C0618F8-A8A1-424E-99C2-9BD5EC1D0107"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha9:*:*:*:*:*:*",
"matchCriteriaId": "1D69BFE3-1049-4A6A-B0C6-DD19C42841D8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "245EB59F-6C85-4ADB-9CF8-BC14BCA0F95A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "2730BF92-BCE5-4AAE-BE01-247DC88E1930"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta3:*:*:*:*:*:*",
"matchCriteriaId": "0AEF426E-6BC3-430A-A6CB-A191878336F5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta4:*:*:*:*:*:*",
"matchCriteriaId": "AB2FA8BF-3C02-4D2C-87FF-AC5AF93969BC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta5:*:*:*:*:*:*",
"matchCriteriaId": "8A99CFB3-19B9-4795-918C-3EBA7CCEEEF7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:alpha1:*:*:*:*:*:*",
"matchCriteriaId": "B8041C24-A94D-4608-95DC-6C88205E6396"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "39317578-B144-4B3A-86CE-DEF08381B0AD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "D281F50A-901C-40C5-B00C-0DBD091660E8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta3:*:*:*:*:*:*",
"matchCriteriaId": "7A3801C8-13A4-4FF6-B37A-F470776C7BC6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta4:*:*:*:*:*:*",
"matchCriteriaId": "CED56E7C-2C14-412B-98E5-1800FE7BC7F0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta5:*:*:*:*:*:*",
"matchCriteriaId": "608290B9-AA27-439A-AA69-2EA1FAF8D9BC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta6:*:*:*:*:*:*",
"matchCriteriaId": "64FF1CA1-79CB-4626-AE4C-A565872798C9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta7:*:*:*:*:*:*",
"matchCriteriaId": "C4A69805-93E3-49ED-8BBC-FDE1C2704B2D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta8:*:*:*:*:*:*",
"matchCriteriaId": "917E083C-B1A3-4F5A-93D1-D8FB4FC2B313"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta9:*:*:*:*:*:*",
"matchCriteriaId": "791BA3D2-D50A-4ABA-BC4A-44469C09EA6A"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/resiprocate/resiprocate/commit/d67a9ca6fd06ca65d23e313bdbad1ef4dd3aa0df",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://list.resiprocate.org/archive/resiprocate-users/msg02700.html",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}