PT-2017-13400 · Yadifa · Yadifa

Ca0S

+3

·

Published

2017-09-20

·

Updated

2019-10-03

·

CVE-2017-14339

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions YADIFA versions prior to 2.2.6
Description The issue is related to the DNS packet parser, which does not check for infinite pointer loops. This allows an attacker to force the server into an infinite loop, resulting in high CPU usage and making the server unresponsive.
Recommendations For versions prior to 2.2.6, update to version 2.2.6 or later to resolve the issue.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14339
DSA-4001-1

Affected Products

Yadifa