CVE-2017-12865

CRITICAL9.8EPSS 5.0%

connman - security update

Published: 8/29/2017Modified: 3/9/2026
Also known as:DSA-3956-1DEBIAN-CVE-2017-12865DLA-1078-1

Description

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (1)