CVE-2008-5297

No-IP DUC <2.1.7 - RCE

Title source: llm

Description

Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by XenoMuta · cremotelinux
https://www.exploit-db.com/exploits/7151

Scores

EPSS 0.1577
EPSS Percentile 94.7%

Details

CWE
CWE-119
Status published
Products (4)
vitalwerks/no-ip_duc 2.0.3
vitalwerks/no-ip_duc 2.1
vitalwerks/no-ip_duc 2.1.5
vitalwerks/no-ip_duc < 2.1.7
Published Dec 01, 2008
Tracked Since Feb 18, 2026