CVE-2017-9671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
17/07/2017
Last modified:
20/04/2025

Description

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:alpinelinux:alpine_linux:-:*:*:*:*:*:*:*