PT-2019-19840 · Tinysvcmdns · Tinysvcmdns

Publicado

2019-03-13

·

Atualizado

2019-03-15

·

CVE-2019-9748

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions tinysvcmdns versions prior to 2018-01-16
Description The issue allows an mDNS server to perform arbitrary data read operations up to 16383 bytes from the start of the buffer when processing a crafted packet. This can cause a segmentation fault in the uncompress nlabel function in mdns.c, leading to a server crash, or result in the disclosure of memory content via error messages or a server response.
Recommendations For tinysvcmdns versions prior to 2018-01-16, consider disabling the mDNS server functionality until a maintained alternative is implemented, as the project is un-maintained and has known vulnerabilities.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9748

Produtos afetados

Tinysvcmdns