vendor:
Dnss Domain Name Search Software
by:
Ismail Tasdelen
5.5
CVSS
MEDIUM
Denial of Service
DoS
CWE
Product Name: Dnss Domain Name Search Software
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:nsauditor:dnss
Platforms Tested: Windows 10
2020
Dnss Domain Name Search Software – ‘Name’ Denial of Service (PoC)
The Dnss Domain Name Search Software is prone to a denial-of-service (DoS) vulnerability. This allows remote attackers to crash the application by providing a specially crafted value for the 'Name' field. A proof-of-concept (PoC) exploit is provided in the form of a Python script that creates a file containing a payload of 1000 characters and causes the application to crash when the payload is copied into the 'Name' field.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid inputting large amounts of data into the 'Name' field in the Dnss Domain Name Search Software.