vendor:
DNSTracer
by:
Hosein Askari (FarazPajohan)
9,8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: DNSTracer
Affected Version From: 1.8.1
Affected Version To: 1.9
Patch Exists: No
Related CWE: CVE-2017-9430
CPE: a:mavetju:dnstracer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Parrot OS
2017
DNSTracer Stack-based Buffer Overflow
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.
Mitigation:
No mitigation available