{ "id": "CVE-2017-9454", "sourceIdentifier": "cve@mitre.org", "published": "2017-08-18T14:29:00.843", "lastModified": "2019-12-11T22:14:59.490", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DNS response." }, { "lang": "es", "value": "Un desbordamiento de b\u00fafer en la funci\u00f3n ares_parse_a_reply en la biblioteca embebida ares en ReSIProcate en versiones anteriores a la 1.12.0 permite que atacantes remotos provoquen una denegaci\u00f3n de servicio (lectura fuera de l\u00edmites) mediante una respuesta DNS manipulada." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-125" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.10.2", "matchCriteriaId": "D7A9B784-2E65-4DD9-A2BF-37E9423059E9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha1:*:*:*:*:*:*", "matchCriteriaId": "EBC4049D-A7EE-4E51-82F1-3431B4571C55" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha10:*:*:*:*:*:*", "matchCriteriaId": "2A32D09D-AFFE-407D-908F-8191D2973C27" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha11:*:*:*:*:*:*", "matchCriteriaId": "3885433A-D1DE-4970-84AF-A7D6DFAF1B57" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha2:*:*:*:*:*:*", "matchCriteriaId": "7A6DE94C-6DCB-4668-A326-9E001283C822" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha3:*:*:*:*:*:*", "matchCriteriaId": "888FA5FD-51E9-4185-ADA1-D668997EB4D8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha4:*:*:*:*:*:*", "matchCriteriaId": "4402C7AC-9011-4D24-A480-4345E53CCDB1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha5:*:*:*:*:*:*", "matchCriteriaId": "887E4C3A-421B-45FA-B15A-B28C5441690D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha6:*:*:*:*:*:*", "matchCriteriaId": "3DF27A62-D822-4EC6-B9B0-8B649E4D1945" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha7:*:*:*:*:*:*", "matchCriteriaId": "A56BD5AA-5147-46E7-8A9C-D7659910F47E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha8:*:*:*:*:*:*", "matchCriteriaId": "2C0618F8-A8A1-424E-99C2-9BD5EC1D0107" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:alpha9:*:*:*:*:*:*", "matchCriteriaId": "1D69BFE3-1049-4A6A-B0C6-DD19C42841D8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "245EB59F-6C85-4ADB-9CF8-BC14BCA0F95A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "2730BF92-BCE5-4AAE-BE01-247DC88E1930" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta3:*:*:*:*:*:*", "matchCriteriaId": "0AEF426E-6BC3-430A-A6CB-A191878336F5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta4:*:*:*:*:*:*", "matchCriteriaId": "AB2FA8BF-3C02-4D2C-87FF-AC5AF93969BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.11.0:beta5:*:*:*:*:*:*", "matchCriteriaId": "8A99CFB3-19B9-4795-918C-3EBA7CCEEEF7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:alpha1:*:*:*:*:*:*", "matchCriteriaId": "B8041C24-A94D-4608-95DC-6C88205E6396" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "39317578-B144-4B3A-86CE-DEF08381B0AD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "D281F50A-901C-40C5-B00C-0DBD091660E8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta3:*:*:*:*:*:*", "matchCriteriaId": "7A3801C8-13A4-4FF6-B37A-F470776C7BC6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta4:*:*:*:*:*:*", "matchCriteriaId": "CED56E7C-2C14-412B-98E5-1800FE7BC7F0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta5:*:*:*:*:*:*", "matchCriteriaId": "608290B9-AA27-439A-AA69-2EA1FAF8D9BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta6:*:*:*:*:*:*", "matchCriteriaId": "64FF1CA1-79CB-4626-AE4C-A565872798C9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta7:*:*:*:*:*:*", "matchCriteriaId": "C4A69805-93E3-49ED-8BBC-FDE1C2704B2D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta8:*:*:*:*:*:*", "matchCriteriaId": "917E083C-B1A3-4F5A-93D1-D8FB4FC2B313" }, { "vulnerable": true, "criteria": "cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta9:*:*:*:*:*:*", "matchCriteriaId": "791BA3D2-D50A-4ABA-BC4A-44469C09EA6A" } ] } ] } ], "references": [ { "url": "https://github.com/resiprocate/resiprocate/commit/d67a9ca6fd06ca65d23e313bdbad1ef4dd3aa0df", "source": "cve@mitre.org", "tags": [ "Patch", "Third Party Advisory" ] }, { "url": "https://list.resiprocate.org/archive/resiprocate-users/msg02700.html", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] } ] }