MNBSD-2014-15: rtsold stack buffer overflow via crafted router advertisement

Severity: Unknown

Affected Package: rtsold

Summary: rtsold stack buffer overflow via crafted router advertisement

Description

Due to a missing length check in the code handling DNS parameters, a malformed router advertisement message could result in a stack buffer overflow in rtsold(8). A remote attacker on the local network could exploit this to crash the daemon or potentially execute code.

Affected Versions

rtsold

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2014-3954

Published: October 21, 2014
Last Modified: October 21, 2014