CVE-2017-9334: Call-Cc Chicken
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.
Affected products
- Call-Cc Chicken: up to and including 4.12.0
Published 2017-06-01. Last modified 2026-06-17.