5
CVSSv2

CVE-2017-7458

Published: 26/06/2017 Updated: 29/06/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng prior to 3.0 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ntop ntopng

Vendor Advisories

Debian Bug report logs - #866722 ntopng: CVE-2017-7416 Package: src:ntopng; Maintainer for src:ntopng is Ludovico Cavedon <cavedon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 1 Jul 2017 08:27:02 UTC Severity: important Tags: fixed-upstream, moreinfo, security, upstream Found in ver ...
Debian Bug report logs - #866721 ntopng: CVE-2017-7458 Package: src:ntopng; Maintainer for src:ntopng is Ludovico Cavedon <cavedon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 1 Jul 2017 08:15:01 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Found in versio ...
Debian Bug report logs - #866719 ntopng: CVE-2017-7459: HTTP Response Splitting Package: src:ntopng; Maintainer for src:ntopng is Ludovico Cavedon <cavedon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 1 Jul 2017 07:57:02 UTC Severity: important Tags: security, upstream Found in vers ...