Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit.
| Software | From | Fixed in |
|---|---|---|
| nsasoft / nsauditor | 3.0.28 | 3.0.28.x |
| nsasoft / nsauditor | 3.2.1.0 | 3.2.1.0.x |