← All CVEs

CVE-2008-5297

high · 7.6

Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.

7.6
CVSS
18.5%
EPSS (exploit prob.)
97th
EPSS percentile
2008-12-01
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
vitalwerksno-ip_duc<= 2.1.7
vitalwerksno-ip_duc2.0.3
vitalwerksno-ip_duc2.1
vitalwerksno-ip_duc2.1.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-5297