PT-2019-10742 · Cujo · Cujo Smart Firewall
CVE-2018-4002
·
Publicado
2019-10-31
·
Atualizado
2023-02-03
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
CUJO Smart Firewall version 7003
Description
A denial-of-service issue exists due to unsafe handling of label compression pointers in mDNS packets by the mdnscap binary, leading to uncontrolled recursion and eventual stack exhaustion, causing the mdnscap process to crash. An unauthenticated attacker can trigger this issue by sending a specially crafted mDNS message.
Recommendations
For CUJO Smart Firewall version 7003, consider disabling the mdnscap binary or restricting its access to mDNS packets until a fix is available.
Exploit
Correção
Uncontrolled Recursion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cujo Smart Firewall