CVE-2017-16100

CRITICAL

dns-sync < 0.1.1 - OS Command Injection via resolve() Method

Title source: llm
STIX 2.1

Description

dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/skoranga/node-dns-sync/issues/5
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/523

Scores

CVSS v3 9.8
EPSS 0.0513
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77 CWE-94
Status published
Products (2)
dns-sync_project/dns-sync < 0.1.1
npm/dns-sync 0 - 0.1.1npm
Published Jun 07, 2018
Tracked Since Feb 18, 2026