CVE-2019-25341
7.5iNetTools · iNetTools for iOS
A stack-based buffer overflow in the Whois feature of iNetTools for iOS 8.20 allows an attacker to cause an application crash by providing a specially crafted 98-character input string.
Executive summary
iNetTools for iOS 8.20 is vulnerable to a denial of service attack through a stack-based buffer overflow, which may cause the application to crash upon processing malicious input.
Vulnerability
The application contains a stack-based buffer overflow (CWE-121) within the Whois functionality. By inputting a 98-character buffer into the Domain Name field, an unauthenticated user can trigger an application crash.
Business impact
The vulnerability results in a denial of service condition for the affected iOS application. While the CVSS score of 7.5 indicates a high severity due to the impact on availability, the practical business impact is limited to the local disruption of the iNetTools application on the user's device.
Remediation
Immediate Action: Users should check the Apple App Store for the latest version of iNetTools and update the application if a patched version is available.
Proactive Monitoring: Security teams should monitor for unauthorized or unusual application behavior on managed mobile devices if these tools are deployed in a corporate environment.
Compensating Controls: Avoid using the Whois feature with untrusted or suspicious domain name inputs until the software has been updated to a secure version.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit Database (EDB-ID: 47716).
Analyst recommendation
Given the availability of a public proof-of-concept exploit, the risk of application disruption is credible. Organizations and individual users should prioritize updating the application to the latest available version to eliminate this vulnerability and restore stability to the Whois feature.
Sources
Originally found and disclosed by Ivan Marmolejo, per the CVE Program record.
- ExploitDB-47716 Exploit / PoC
- Official App Store Page
- VulnCheck Advisory: iNetTools for iOS 8.20 - 'Whois' Denial of Service Third-party advisory