vendor:
DIG
by:
Rafael Pedrero
7.5
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: DIG
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: YES
Related CWE: N/A
CPE: a:necrosoft:dig
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3
2005
Necrosoft DIG v0.4 – Denial of Service (PoC) SEH overwritten Crash PoC
Necrosoft DIG v0.4 is vulnerable to a denial of service attack due to a buffer overflow vulnerability. By sending a specially crafted payload of 2000 bytes, an attacker can overwrite the SEH handler and cause a crash. This can be done by running Necrosoft DIG v0.4, copying the content of the DIG_Crash.txt file to the clipboard, and pasting it into the 'Target' field. Clicking the 'TCP lookup' button will cause the crash.
Mitigation:
Upgrade to the latest version of Necrosoft DIG v0.4 or apply the appropriate patch.