Back to search
CVE-2008-5297
Published: Dec 1, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20081120 CVE request: no-ip DUC buffer overflow
mailing-list
x_refsource_MLIST
32344
vdb-entry
x_refsource_BID
33610
third-party-advisory
x_refsource_SECUNIA
4672
third-party-advisory
x_refsource_SREASON
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506179
x_refsource_CONFIRM
33138
third-party-advisory
x_refsource_SECUNIA
GLSA-200901-12
vendor-advisory
x_refsource_GENTOO
7151
exploit
x_refsource_EXPLOIT-DB
DSA-1686
vendor-advisory
x_refsource_DEBIAN
http://xenomuta.tuxfamily.org/exploits/noIPwn3r.c
x_refsource_MISC
32761
third-party-advisory
x_refsource_SECUNIA
dducl-httpresponse-bo(46696)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now