vendor:
DMitry (Deepmagic Information Gathering Tool)
by:
Hosein Askari (FarazPajohan)
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: DMitry (Deepmagic Information Gathering Tool)
Affected Version From: 1.3a
Affected Version To: 1.3a
Patch Exists: NO
Related CWE: CVE-2017-7938
CPE: a:dmitry_project:dmitry:1.3a
Platforms Tested: Unix
2017
Dmitry(Deepmagic Information Gathering Tool) Local Stack Buffer Overflow
Buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.
Mitigation:
Update to a patched version of DMitry or apply security patches provided by the vendor. Avoid passing long arguments to DMitry.