Description
DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can trigger a denial of service by pasting a malicious registration code containing 300 repeated characters into the Name/Key field via the Register menu option.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46831 (ExploitDB-46831)
www.nsauditor.com/downloads/dnss_setup.exe (Product Reference)
www.vulncheck.com/...-name-search-software-denial-of-service (VulnCheck Advisory: DNSS Domain Name Search Software 2.1.8 Denial of Service)