CVE-2017-7458: Null Pointer Dereference
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7458?
CVE-2017-7458 is classified as a denial of service vulnerability due to a NULL pointer dereference leading to application crashes.
How do I fix CVE-2017-7458?
To fix CVE-2017-7458, update ntopng to version 3.0 or later to address the vulnerability.
What software is affected by CVE-2017-7458?
CVE-2017-7458 affects ntopng versions prior to 3.0, specifically versions up to and including 2.4.
What type of attack does CVE-2017-7458 enable?
CVE-2017-7458 enables remote attackers to execute a denial of service attack.
How can a remote attacker exploit CVE-2017-7458?
A remote attacker can exploit CVE-2017-7458 by sending a request with an empty field that should contain a hostname or IP address.