VDB
CVE-2007-2362
CVE-2007-2362
PUBLISHED
CVSS 9 CRITICAL
Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.
EPSS 22.17% · 95.9th percentile
Risk Scores
CVSS 2.0
9
EPSS Score
22.17%
95.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| don_moore | mydns | 1.1.0 |
| n/a | n/a | n/a |
Timeline
- Apr 30, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 31, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Aug 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- mydns-update-bo(33933) vdb
- 35439 vdb
- 20070427 mydns-1.1.0 remote heap overflow mailing-list
- 2658 third-party-advisory
- 23694 vdb
- DSA-1434 vendor-advisory
- 25007 third-party-advisory
- ADV-2007-1561 vdb
- http://www.digit-labs.org/files/exploits/mydns-rr-smash.c url
- 35438 vdb
- 28086 third-party-advisory
- http://www.digit-labs.org/files/patches/mydns-update.c.diff url
- https://nvd.nist.gov/vuln/detail/CVE-2007-2362 advisory