CVE-2017-12130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
20/01/2018
Last modified:
14/12/2022

Description

An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially crafted packet can make the library dereference a NULL pointer leading to a server crash and denial of service. An attacker needs to send a DNS query to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tinysvcmdns_project:tinysvcmdns:2017-11-05:*:*:*:*:*:*:*