PT-2005-1859 · Xzabite · Xzabite Dyndnsupdate

Toby Dickenson

·

Published

2005-03-22

·

Updated

2008-09-05

·

CVE-2005-0830

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xzabite DYNDNSUpdate versions 0.6.15 and earlier
Description The issue is related to multiple buffer overflows, including the ipcheck function in dyndnsupdate.c. This allows remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.
Recommendations For Xzabite DYNDNSUpdate versions 0.6.15 and earlier, consider disabling the ipcheck function in dyndnsupdate.c as a temporary workaround until a patch is available. Restrict access to the dyndns.org server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0830

Affected Products

Xzabite Dyndnsupdate