{"api_version":"1","generated_at":"2026-07-23T06:06:05+00:00","cve":"CVE-2017-14339","urls":{"html":"https://cve.report/CVE-2017-14339","api":"https://cve.report/api/cve/CVE-2017-14339.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14339","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14339"},"summary":{"title":"CVE-2017-14339","description":"The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-09-20 16:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-835"],"metrics":[],"references":[{"url":"https://www.tarlogic.com/blog/fuzzing-yadifa-dns/","name":"https://www.tarlogic.com/blog/fuzzing-yadifa-dns/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"Fuzzing Tales 0x01: Yadifa DNS - Tarlogic Security - Ciberseguridad y Hacking ético","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2017/dsa-4001","name":"DSA-4001","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4001-1 yadifa","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/yadifa/yadifa/blob/v2.2.6/ChangeLog","name":"https://github.com/yadifa/yadifa/blob/v2.2.6/ChangeLog","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"yadifa/ChangeLog at v2.2.6 · yadifa/yadifa · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14339","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14339","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14339","vulnerable":"1","versionEndIncluding":"2.2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yadifa","cpe5":"yadifa","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-14339","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/yadifa/yadifa/blob/v2.2.6/ChangeLog","refsource":"CONFIRM","url":"https://github.com/yadifa/yadifa/blob/v2.2.6/ChangeLog"},{"name":"https://www.tarlogic.com/blog/fuzzing-yadifa-dns/","refsource":"MISC","url":"https://www.tarlogic.com/blog/fuzzing-yadifa-dns/"},{"name":"DSA-4001","refsource":"DEBIAN","url":"http://www.debian.org/security/2017/dsa-4001"}]}},"nvd":{"publishedDate":"2017-09-20 16:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-835"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":7.8},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:yadifa:yadifa:*:*:*:*:*:*:*:*","versionEndIncluding":"2.2.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14339","Ordinal":"111771","Title":"CVE-2017-14339","CVE":"CVE-2017-14339","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14339","Ordinal":"1","NoteData":"The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14339","Ordinal":"2","NoteData":"2017-09-20","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14339","Ordinal":"3","NoteData":"2017-11-03","Type":"Other","Title":"Modified"}]}}}