PT-2005-1859 · Xzabite · Xzabite Dyndnsupdate
Toby Dickenson
·
Publicado
2005-03-22
·
Atualizado
2008-09-05
·
CVE-2005-0830
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xzabite DYNDNSUpdate versions 0.6.15 and earlier
Description
The issue is related to multiple buffer overflows, including the
ipcheck function in dyndnsupdate.c. This allows remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.Recommendations
For Xzabite DYNDNSUpdate versions 0.6.15 and earlier, consider disabling the
ipcheck function in dyndnsupdate.c as a temporary workaround until a patch is available. Restrict access to the dyndns.org server to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xzabite Dyndnsupdate