{"id":"CVE-2014-9682","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-9682","summary":"dns-sync command injection vulnerability","details":"The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.","published":"2017-10-24T18:33:36Z","modified":"2023-11-08T03:57:47.247050Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"dns-sync","fixedVersion":"0.1.1"}],"fix":{"url":"https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d","label":"skoranga/node-dns-sync@d9abaae"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9682"},{"type":"WEB","url":"https://github.com/skoranga/node-dns-sync/issues/1"},{"type":"WEB","url":"https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q5pq-pgrv-fh89"},{"type":"PACKAGE","url":"https://github.com/skoranga/node-dns-sync"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/11/11/6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:47.247050Z"}}