The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted host.
[
{
"digest": {
"function_hash": "123800384529793006410117634612540534421",
"length": 945.0
},
"target": {
"file": "bin/gssstdio.c",
"function": "gstd_accept"
},
"deprecated": false,
"source": "https://github.com/elric1/knc/commit/f237f3e09ecbaf59c897f5046538a7b1a3fa40c1",
"id": "CVE-2017-9732-37919fc3",
"signature_version": "v1",
"signature_type": "Function"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"193799561628629852479905158744006122511",
"10597813081131531540646423760232605634",
"13573681778233594011506153502873435606",
"285112487704076807788069812916150694958",
"93295609652909022966029026078006397357",
"289242926332152215964813883197495632417",
"22590990038414799912061306650990009437",
"164423696563241641726662970012386914655",
"49947171259944620647834468293325178165",
"86890169374550955677045141749488235756",
"2895638651869158130765015203162897697",
"274561984334575226663321507064138975632",
"5757969317131918796589408999278329281",
"210938770927126775792901958772536434130",
"83331737250803275823573953085196139961",
"322191407948263273819520789056478452798",
"323576057902805582100152926152097203966",
"275401222835303868878633321197210292390",
"337215776742961844823239197230091682831",
"133270039927477131143880844442986168661",
"226026858247104887886310288651172892935",
"259179943245552260550822538766535424733",
"208231167390164692998667839998750530827",
"191379491175918729520835353402900443509",
"94804679831800844402563612168042448081",
"238416794821828689689489520802156602355",
"148707164122125843103861583319126903883",
"205539226584804908093314219838739033973",
"164423696563241641726662970012386914655",
"49947171259944620647834468293325178165",
"86890169374550955677045141749488235756",
"188110936949729058450265077228667690706",
"198523024209352012393123259534839309704",
"9019923645297037727063630572143203365",
"84799375509267989226819191491904897781",
"3870698890658043202180568282265758000",
"260546729310675582902553108396950718560",
"291054121200305771741495444056588044361",
"280905277838797282035067220239931704774",
"12959958512253090950050503865149492001"
]
},
"target": {
"file": "bin/gssstdio.c"
},
"deprecated": false,
"source": "https://github.com/elric1/knc/commit/f237f3e09ecbaf59c897f5046538a7b1a3fa40c1",
"id": "CVE-2017-9732-81592b9b",
"signature_version": "v1",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "165427235488136539998141578923711309738",
"length": 1457.0
},
"target": {
"file": "bin/gssstdio.c",
"function": "read_packet"
},
"deprecated": false,
"source": "https://github.com/elric1/knc/commit/f237f3e09ecbaf59c897f5046538a7b1a3fa40c1",
"id": "CVE-2017-9732-cb1fd364",
"signature_version": "v1",
"signature_type": "Function"
}
]