VYPR

emdns

by emdns

CVEs (1)

  • CVE-2023-50434CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.00

    emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The impact could vary…