Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3910

Опубликовано: 04 сент. 2008
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hsc:dns2tcp:*:*:*:*:*:*:*:*
Версия до 0.4 (включая)

EPSS

Процентиль: 83%
0.02433
Низкий

10 Critical

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
почти 18 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

debian
почти 18 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a cer ...

github
больше 4 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

EPSS

Процентиль: 83%
0.02433
Низкий

10 Critical

CVSS2

Дефекты

CWE-189