Junglewise Threat Intelligence

CVE-2018-25423: ArmCode Arm Whois buffer overflow in domain input field

CVE-2018-25423 · Severity: medium · CVSS 6.2 · Published 2026-05-30

Executive brief

Arm Whois, a utility used to retrieve registration and ownership information for IP addresses and domains, is vulnerable to a buffer overflow. A local user can crash the application by entering an excessively long string into the search field. This results in a denial-of-service condition, preventing the software from functioning until it is restarted.

Technical details

A classic buffer overflow (CWE-120) exists in Arm Whois version 3.11 and potentially earlier versions. The vulnerability is located in the input handling for the 'IP address or domain' field, where the application fails to validate the length of the input string before copying it into a fixed-size buffer. An attacker with local access can trigger this by pasting a string of approximately 700 bytes and initiating a lookup. This results in memory corruption and an application crash (Denial of Service). While the current exploit is a Proof of Concept for DoS, buffer overflows of this nature can sometimes be leveraged for arbitrary code execution depending on the memory protections in place on the host OS.

Affected products

  • ArmCode Arm Whois 3.11 and earlier

Timeline

  • 2018-10-31: disclosed: Initial Proof of Concept discovered by Yair Rodríguez Aparicio
  • 2018-11-01: other: Exploit published to Exploit-DB
  • 2026-05-30: advisory: CVE record published and enriched by VulnCheck/NVD

References