7.5
CVSSv2

CVE-2017-7938

Published: 20/04/2017 Updated: 30/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows malicious users to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mor-pah.net dmitry deepmagic information gathering tool 1.3a

Vendor Advisories

Debian Bug report logs - #1070370 dmitry: CVE-2017-7938 CVE-2020-14931 CVE-2024-31837 Package: src:dmitry; Maintainer for src:dmitry is Debian QA Group <packages@qadebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 4 May 2024 15:57:02 UTC Severity: important Tags: security, upstream Found in ...

Exploits

################ #Exploit Title: Dmitry(Deepmagic Information Gathering Tool) Local Stack Buffer Overflow #CVE: CVE-2017-7938 #CWE: CWE-119 #Exploit Author: Hosein Askari (FarazPajohan) #Vendor HomePage: mor-pahnet/software/dmitry-deepmagic-information-gathering-tool/ #Version : 13a (Unix) #Exploit Tested on: Parrot OS #Date: 19-04-2017 # ...
Dmitry (Deepmagic Information Gathering Tool) version 13a suffers from a local stack buffer overflow vulnerability ...