CVE-2017-17066
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading sensitive router memory, aka the GarlicRust bug.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.22% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- getkovri/kovri · i2pd/i2pd
- Source
- cve@mitre.org
References
- https://eyalitkin.wordpress.com/2017/12/04/cve-publication-garlicrust-cve-2017-17066/Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/291489Issue Tracking, Third Party Advisory
- https://eyalitkin.wordpress.com/2017/12/04/cve-publication-garlicrust-cve-2017-17066/Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/291489Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.