dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
References
Link | Resource |
---|---|
https://github.com/skoranga/node-dns-sync/issues/5 | Exploit Third Party Advisory |
https://nodesecurity.io/advisories/523 | Third Party Advisory |
https://github.com/skoranga/node-dns-sync/issues/5 | Exploit Third Party Advisory |
https://nodesecurity.io/advisories/523 | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/skoranga/node-dns-sync/issues/5 - Exploit, Third Party Advisory | |
References | () https://nodesecurity.io/advisories/523 - Third Party Advisory |
Information
Published : 2018-06-07 02:29
Updated : 2024-11-21 03:15
NVD link : CVE-2017-16100
Mitre link : CVE-2017-16100
CVE.ORG link : CVE-2017-16100
JSON object : View
Products Affected
dns-sync_project
- dns-sync