CVE-2017-14339
Summary
| CVE | CVE-2017-14339 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-20 16:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive. |
Risk And Classification
Problem Types: CWE-835
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fuzzing Tales 0x01: Yadifa DNS - Tarlogic Security - Ciberseguridad y Hacking ético | MISC | www.tarlogic.com | Exploit, Technical Description, Third Party Advisory |
| Debian -- Security Information -- DSA-4001-1 yadifa | DEBIAN | www.debian.org | |
| yadifa/ChangeLog at v2.2.6 · yadifa/yadifa · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.