CVE-2024-42643

NameCVE-2024-42643
DescriptionInteger Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligned memory access.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1086146

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
smartdns (PTS)bullseye33+dfsg-2.1vulnerable
bookworm40+dfsg-1vulnerable
sid, trixie46+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
smartdnssource(unstable)(unfixed)1086146

Notes

https://github.com/pymumu/smartdns/issues/177
possibly valid report as upstream issue has been closed, but details unclear

Search for package or bug name: Reporting problems