Cesanta Mongoose DNS Compressed Name Denial of Service (CVE-2017-2909)

An infinite loop vulnerability exists in the DNS server functionality of Cesanta Mongoose. The vulnerability is due to insufficient handling of compressed names in DNS queries and responses. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted DNS query or response to an application implementing the Mongoose DNS server functionality or DNS client functionality, respectively.

from Check Point Update Services Advisories http://ift.tt/2kuA7wo

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...