vendor:
NECROSOFT NScan
by:
John Page aka HYP3RLINX
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: NECROSOFT NScan
Affected Version From: <= v0.9.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:nscan.hypermart.net:nscan
Platforms Tested: Windows
Unknown
Buffer Overflow in NECROSOFT NScan
The dig.exe component of NECROSOFT NScan version <= v0.9.1 is vulnerable to a buffer overflow. By sending a specially crafted payload to the 'Target' input field in the DNS lookup, an attacker can overwrite the EIP register and execute arbitrary code.
Mitigation:
Update to a version higher than v0.9.1 or apply a patch from the vendor.