Executive brief
Nsasoft Dnss Domain Name Search Software, a tool used for network auditing and domain lookups, is vulnerable to a crash when processing long registration names. An attacker can cause the application to stop functioning by entering a specially crafted 1,000-character string into the registration name field. This results in a denial of service, preventing legitimate users from using the software until it is restarted.
Technical details
A classic buffer overflow (CWE-120) exists in Nsasoft Dnss Domain Name Search Software due to insufficient input validation in the registration interface. The vulnerability is triggered when a user inputs a string exceeding 1,000 characters into the 'Name' field during the registration process. While some sources categorize the attack vector as local due to the requirement of interacting with the application UI, others note the lack of authentication requirements. Successful exploitation results in a memory corruption that crashes the application process, leading to a denial of service. A public Proof of Concept (PoC) exists demonstrating the crash using a 1,000-byte payload.
Affected products
- Nsasoft (Nsauditor) Dnss Domain Name Search Software All versions up to and including 2020 releases
Timeline
- 2020-01-06: disclosed: Initial exploit and PoC published on Exploit-DB
- 2026-02-11: advisory: CVE published and NVD entry created