Vulnerability Description
SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pymumu | Smartdns | <= 41 |
Related Weaknesses (CWE)
References
- https://github.com/pymumu/smartdns/commit/56d0332bf91104cfc877635f6c82e9348587dfPatch
- https://github.com/pymumu/smartdns/issues/1378Exploit
- https://github.com/pymumu/smartdns/commit/56d0332bf91104cfc877635f6c82e9348587dfPatch
- https://github.com/pymumu/smartdns/issues/1378Exploit
FAQ
What is CVE-2023-31470?
CVE-2023-31470 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.
How severe is CVE-2023-31470?
CVE-2023-31470 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-31470?
Check the references section above for vendor advisories and patch information. Affected products include: Pymumu Smartdns.