CVE-2017-7938

medium
Published 2017-04-20 · Modified 2026-05-13
CVSS v3
6.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
CVSS v2
7.5
VIR risk
6.6

Description

Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.

Predictions

Exploit likelihood
65%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-7938

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.3a-1.2+deb12u1
debian debianbullseyefixed1.3a-1.1+deb11u1
debian debianforkyfixed1.3a-5
debian debiansidfixed1.3a-5
debian debiantrixiefixed1.3a-5

Application impact

VendorProductVersionsFixed
mor-pah.netdmitry_deepmagic_information_gathering_tool1.3a

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.