CVE Vulnerabilities

CVE-2017-1000232

Double Free

Published: Nov 17, 2017 | Modified: Apr 01, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Ldns Nlnetlabs 1.7.0 (including) 1.7.0 (including)
Ldns Ubuntu artful *
Ldns Ubuntu devel *
Ldns Ubuntu trusty *
Ldns Ubuntu upstream *
Ldns Ubuntu xenial *
Ldns Ubuntu zesty *

Potential Mitigations

References