Input validation error - CVE-2017-9334

 

Input validation error - CVE-2017-9334

Published: June 1, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33507
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9334
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.


Affected software

chicken (Alpine package)
chicken
Fedora

How to mitigate CVE-2017-9334

Install update from vendor's website.

chicken (Alpine package) - update to 4.12.0-r2
chicken - update to 5.0.0-2.fc29

External References

Related Security Bulletins