ZeroHour
Cisco Talospublished ()ingested Nick Biasini

Vulnerability Spotlight: Tinysvcmdns Multi

highVulnerability exploited in the wildimportance 60CVE-2017-12130

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-12130
An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05.

An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially crafted packet can make the library dereference a NULL pointer leading to a server crash and denial of service. An attacker needs to send a DNS query to trigger this vulnerability.

NVD description · AI analysis pending
7.52% PoC
  • tinysvcmdns project tinysvcmdns
Full article169 words · extracted from blog.talosintelligence.com · click to collapse

Wednesday, January 17, 2018 12:46

Overview

Talos is disclosing a single NULL pointer dereference vulnerability in the tinysvcmdns library. Tinysvcmdns is a tiny MDNS responder implementation for publishing services. This is essentially a mini and embedded version of Avahi or Bonjour.

Details

Discovered by Claudio Bozzato, Yves Younan, Lilith Wyatt, and Aleksandar Nikolic of Cisco Talos.

TALOS-2017-0486 / CVE-2017-12130 is a NULL pointer dereference vulnerability in the tinysvcmdns library. The vulnerability lies in the way that tinysvcmdns parses labels in DNS requests. This issue results in a NULL pointer, which when dereferenced results in a denial of service. An attacker could trigger this vulnerability by sending a specially crafted DNS query. Full details of the vulnerability are available here.

Coverage

The following Snort rules will detect exploitation attempts. Note that additional rules may be released at a future date, and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.

Snort Rule: 44986

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vuln-spotlight-tinysvcmdns/