Vulnerability Description
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mor-Pah.Net | Dmitry Deepmagic Information Gathering Tool | 1.3a |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/issue/WLB-2017040113ExploitThird Party Advisory
- https://github.com/jaygreig86/dmitry/pull/12
- https://packetstormsecurity.com/files/142210/Dmitry-1.3a-Local-Stack-Buffer-OverExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41898/
- https://cxsecurity.com/issue/WLB-2017040113ExploitThird Party Advisory
- https://github.com/jaygreig86/dmitry/pull/12
- https://lists.debian.org/debian-lts-announce/2024/10/msg00024.html
- https://packetstormsecurity.com/files/142210/Dmitry-1.3a-Local-Stack-Buffer-OverExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41898/
FAQ
What is CVE-2017-7938?
CVE-2017-7938 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other im...
How severe is CVE-2017-7938?
CVE-2017-7938 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7938?
Check the references section above for vendor advisories and patch information. Affected products include: Mor-Pah.Net Dmitry Deepmagic Information Gathering Tool.