The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
References
Link | Resource |
---|---|
https://github.com/ntop/ntopng/commit/01f47e04fd7c8d54399c9e465f823f0017069f8f | Issue Tracking Release Notes Patch Third Party Advisory |
https://github.com/ntop/ntopng/blob/3.0/CHANGELOG.md | Issue Tracking Patch Third Party Advisory |
Configurations
Information
Published : 2017-06-26 16:29
Updated : 2017-06-29 08:31
NVD link : CVE-2017-7458
Mitre link : CVE-2017-7458
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
ntop
- ntopng