CVE-2017-16100

EPSS 5.3%

Command Injection in dns-sync

Published: 7/18/2018Modified: 11/8/2023

Description

Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method. ## Recommendation - Use an alternative dns resolver - Do not allow untrusted input into `dns-sync.resolve()`

Affected packages (1)

References (9)