PT-2005-1859 · Xzabite · Xzabite Dyndnsupdate
Toby Dickenson
·
Published
2005-03-22
·
Updated
2008-09-05
·
CVE-2005-0830
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xzabite DYNDNSUpdate versions 0.6.15 and earlier
Description
The issue is related to multiple buffer overflows, including the
ipcheck function in dyndnsupdate.c. This allows remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.Recommendations
For Xzabite DYNDNSUpdate versions 0.6.15 and earlier, consider disabling the
ipcheck function in dyndnsupdate.c as a temporary workaround until a patch is available. Restrict access to the dyndns.org server to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xzabite Dyndnsupdate