CVE-2017-12865
CRITICALIntel Connman < 1.34 - Memory Corruption
Title source: ruleDescription
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.
Exploits (1)
nomisec
WORKING POC
by ManaswiJaiswal · poc
https://github.com/ManaswiJaiswal/Reproducing-ConnMan-1.34
References (7)
Scores
CVSS v3
9.8
EPSS
0.0376
EPSS Percentile
88.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (2)
debian/debian_linux
8.0
intel/connman
< 1.34
Published
Aug 29, 2017
Tracked Since
Feb 18, 2026