CVE Vulnerabilities

CVE-2017-1000232

Double Free

Published: Nov 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
LdnsNlnetlabs1.7.0 (including)1.7.0 (including)
LdnsUbuntuartful*
LdnsUbuntudevel*
LdnsUbuntuesm-infra/xenial*
LdnsUbuntutrusty*
LdnsUbuntuupstream*
LdnsUbuntuxenial*
LdnsUbuntuzesty*

Potential Mitigations

References