Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

No-IP Dynamic Update Client for Linux Remote Buffer Overflow Vulnerability

No-IP Dynamic Update Client (DUC) is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check input messages.

An attacker can exploit this issue by enticing an unsuspecting user into connecting to a malicious server. Successful attacks will allow arbitrary code to run within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

DUC 2.1.7 for Linux is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus