|
No-IP Dynamic Update Client for Linux Remote Buffer Overflow Vulnerability
No-IP Dynamic Update Client (DUC) is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check input messages. An attacker can exploit this issue by enticing an unsuspecting user into connecting to a malicious server. Successful attacks will allow arbitrary code to run within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. DUC 2.1.7 for Linux is vulnerable; other versions may also be affected. |
|
|
Privacy Statement |