PT-2025-52453 · Igmpproxy+1 · Igmpproxy+1
Miora-Sora
·
Published
2025-12-19
·
Updated
2025-12-19
·
CVE-2025-50681
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
igmpproxy versions prior to commit 2b30c36
Description
A crafted IGMPv3 membership report packet with a malicious source address can cause a denial of service (application crash). Insufficient validation in the
recv igmp() function in src/igmpproxy.c allows an invalid group record type to trigger a NULL pointer dereference when logging the address using inet fmtsrc(). This can be exploited by sending malformed multicast traffic to a host running igmpproxy, leading to a crash. The software is used in embedded networking environments and consumer-grade IoT devices to handle multicast traffic.Recommendations
Update to a version after commit 2b30c36.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Igmpproxy