CVE-2008-3910

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
04/09/2008
Last modified:
09/04/2025

Description

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hsc:dns2tcp:*:*:*:*:*:*:*:* 0.4 (including)