REDHAT-BUG-2405139: Buffer Overflow
Stack-based Buffer Overflow in lwsadnsparselabel in warmcat libwebsockets allows, when the LWSWITHSYSASYNCDNS flag is enabled during compilation, to overflow the labelstack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2405139?
REDHAT-BUG-2405139 is classified as a high severity vulnerability due to the potential for remote exploitation through stack-based buffer overflow.
What software is affected by REDHAT-BUG-2405139?
The vulnerability REDHAT-BUG-2405139 affects the warmcat libwebsockets software when compiled with the LWS_WITH_SYS_ASYNC_DNS flag enabled.
How do I fix REDHAT-BUG-2405139?
To fix REDHAT-BUG-2405139, update warmcat libwebsockets to a patched version that addresses this buffer overflow issue.
What type of vulnerability is REDHAT-BUG-2405139?
REDHAT-BUG-2405139 is a stack-based buffer overflow vulnerability that can be exploited through malicious DNS responses.
Can exploiting REDHAT-BUG-2405139 lead to data leakage?
Yes, exploiting REDHAT-BUG-2405139 can potentially lead to data leakage or arbitrary code execution depending on the attacker's capabilities.