VDB
CVE-2017-9334
CVE-2017-9334
PUBLISHED
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.
EPSS 0.43% · 63.0th percentile
Risk Scores
EPSS Score
0.43%
63.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | chicken | 4.9.0.1-1, 0 |
Timeline
- Jun 1, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-9334 third-party-advisory
- http://lists.nongnu.org/archive/html/chicken-announce/2017-05/msg00000.html third-party-advisory
- http://lists.nongnu.org/archive/html/chicken-hackers/2017-05/msg00099.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-9334 third-party-advisory