Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3910

Опубликовано: 04 сент. 2008
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hsc:dns2tcp:*:*:*:*:*:*:*:*
Версия до 0.4 (включая)

EPSS

Процентиль: 78%
0.01104
Низкий

10 Critical

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 17 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

debian
больше 17 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a cer ...

github
почти 4 года назад

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

EPSS

Процентиль: 78%
0.01104
Низкий

10 Critical

CVSS2

Дефекты

CWE-189