PT-2019-19840 · Tinysvcmdns · Tinysvcmdns
Publicado
2019-03-13
·
Atualizado
2019-03-15
·
CVE-2019-9748
CVSS v2.0
9.4
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
tinysvcmdns versions prior to 2018-01-16
Description
The issue allows an mDNS server to perform arbitrary data read operations up to 16383 bytes from the start of the buffer when processing a crafted packet. This can cause a segmentation fault in the
uncompress nlabel function in mdns.c, leading to a server crash, or result in the disclosure of memory content via error messages or a server response.Recommendations
For tinysvcmdns versions prior to 2018-01-16, consider disabling the mDNS server functionality until a maintained alternative is implemented, as the project is un-maintained and has known vulnerabilities.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tinysvcmdns