Lucene search

K
cveMitreCVE-2023-31470
HistoryApr 28, 2023 - 9:15 p.m.

CVE-2023-31470

2023-04-2821:15:09
CWE-787
mitre
web.nvd.nist.gov
21
cve-2023-31470
smartdns
buffer overflow
dns request

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

59.7%

SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.

Affected configurations

Nvd
Node
smartdns_projectsmartdnsRange41
VendorProductVersionCPE
smartdns_projectsmartdns*cpe:2.3:a:smartdns_project:smartdns:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

59.7%

Related for CVE-2023-31470