CVE-2017-9732
UnknownEPSS 4.04%
Last modified
CVE-2017-9732 is a vulnerability of currently unknown severity. The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted host.. EPSS estimates a 4.04% chance of exploitation in the next 30 days.
Description
The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted host.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Secure-Endpoints | Kerberised Netcat | < 1.11-1 |
References
- http://packetstormsecurity.com/files/150534/knc-Kerberized-NetCat-Denial-Of-Service.htmlExploit, Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/65Exploit, Mailing List, Patch, Third Party Advisory
- https://github.com/elric1/knc/commit/f237f3e09ecbaf59c897f5046538a7b1a3fa40c1Patch, Third Party Advisory
- https://github.com/irsl/knc-memory-exhaustion/Exploit, Patch, Third Party Advisory
- http://packetstormsecurity.com/files/150534/knc-Kerberized-NetCat-Denial-Of-Service.htmlExploit, Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Nov/65Exploit, Mailing List, Patch, Third Party Advisory
- https://github.com/elric1/knc/commit/f237f3e09ecbaf59c897f5046538a7b1a3fa40c1Patch, Third Party Advisory
- https://github.com/irsl/knc-memory-exhaustion/Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9732?
The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted host.
How severe is CVE-2017-9732?
Severity scoring for CVE-2017-9732 is pending analysis. The EPSS model estimates a 4.04% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9732?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2017-9732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
