PT-2019-10742 · Cujo · Cujo Smart Firewall

CVE-2018-4002

·

Publicado

2019-10-31

·

Atualizado

2023-02-03

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions CUJO Smart Firewall version 7003
Description A denial-of-service issue exists due to unsafe handling of label compression pointers in mDNS packets by the mdnscap binary, leading to uncontrolled recursion and eventual stack exhaustion, causing the mdnscap process to crash. An unauthenticated attacker can trigger this issue by sending a specially crafted mDNS message.
Recommendations For CUJO Smart Firewall version 7003, consider disabling the mdnscap binary or restricting its access to mDNS packets until a fix is available.

Exploit

Correção

Uncontrolled Recursion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-4002

Produtos afetados

Cujo Smart Firewall