Lucene search

K
nvd[email protected]NVD:CVE-2008-3910
HistorySep 04, 2008 - 5:41 p.m.

CVE-2008-3910

2008-09-0417:41:00
CWE-189
web.nvd.nist.gov
4

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.008

Percentile

81.2%

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

Affected configurations

Nvd
Node
hscdns2tcpRange0.4
VendorProductVersionCPE
hscdns2tcp*cpe:2.3:a:hsc:dns2tcp:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.008

Percentile

81.2%