emdns_resolve_raw in emdns.c in... CVE-2023-50434

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The impact could vary depending on the system libraries, compiler, and processor architecture. Code before be565c3 is unaffected.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息