CVE-2017-16100
EPSS 5.3%Command Injection in dns-sync
Published: 7/18/2018Modified: 11/8/2023
Description
Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method. ## Recommendation - Use an alternative dns resolver - Do not allow untrusted input into `dns-sync.resolve()`
Affected packages (1)
- npm/dns-syncfrom 0, < 0.1.1
References (9)
- ADVISORYhttps://github.com/advisories/GHSA-jcw8-r9xm-32c6
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-16100
- WEBhttps://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d
- WEBhttps://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d)))
- WEBhttps://github.com/skoranga/node-dns-sync/issues/1
- WEBhttps://github.com/skoranga/node-dns-sync/issues/1)
- WEBhttps://github.com/skoranga/node-dns-sync/issues/5
- WEBhttps://www.npmjs.com/advisories/153
- WEBhttps://www.npmjs.com/advisories/523