Bugzilla – Bug 1042808
VUL-0: CVE-2017-9430: dnstracer: Stack-based buffer overflow could cause denial of service
Last modified: 2018-10-30 14:02:05 UTC
CVE-2017-9430 Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9430 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9430 https://cxsecurity.com/issue/WLB-2017060030
we have no maintainer for this, would you be willing to submit for this?