HIGH🇬🇧 English

CVE-2019-9747

CVSS 7.5v3.0pub. 2019-03-13upd. 2024-11-21

In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query. When mDNS compressed labels point to each other, the function uncompress_nlabel goes into an infinite loop trying to analyze the packet with an mDNS query. As a result, the mDNS server hangs after receiving the malicious mDNS packet. NOTE: the product's web site states "This project is un-maintained, and has been since 2013. ... There are known vulnerabilities ... You are advised to NOT use this library for any new projects / products."

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Tinysvcmdns Project Tinysvcmdns

    APP
    Tinysvcmdns Project
    ≤ 2018-01-16
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2019-9748CRITICAL9.1PL ✓ten sam produkt

Tinysvcmdns: odczyt pamięci i crash serwera przy przetwarzaniu pakietu mDNS

CVE-2017-12087CRITICAL10.0PL ✓ten sam produkt

Heap overflow w bibliotece tinysvcmdns umożliwiający zapis dowolnych danych

CVE-2017-12130HIGH7.5ten sam produkt

An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A ...