CVE-2020-24383

An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check for proper '\0' termination of the resource record name string, leading to an out-of-bounds read, and potentially causing information leak or Denial-or-Service.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/815128 Third Party Advisory US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/815128 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:butok:fnet:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:14

Type Values Removed Values Added
References () https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 - Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 - Third Party Advisory, US Government Resource
References () https://www.kb.cert.org/vuls/id/815128 - Third Party Advisory, US Government Resource () https://www.kb.cert.org/vuls/id/815128 - Third Party Advisory, US Government Resource

12 Oct 2023, 18:31

Type Values Removed Values Added
First Time Butok fnet
Butok
CPE cpe:2.3:a:fnet_project:fnet:*:*:*:*:*:*:*:* cpe:2.3:a:butok:fnet:*:*:*:*:*:*:*:*

Information

Published : 2020-12-11 23:15

Updated : 2024-11-21 05:14


NVD link : CVE-2020-24383

Mitre link : CVE-2020-24383

CVE.ORG link : CVE-2020-24383


JSON object : View

Products Affected

butok

  • fnet
CWE
CWE-125

Out-of-bounds Read