CVE-2019-25341

7.5

iNetTools · iNetTools for iOS

A stack-based buffer overflow in the Whois feature of iNetTools for iOS 8.20 allows an attacker to cause an application crash by providing a specially crafted 98-character input string.

Executive summary

iNetTools for iOS 8.20 is vulnerable to a denial of service attack through a stack-based buffer overflow, which may cause the application to crash upon processing malicious input.

Vulnerability

The application contains a stack-based buffer overflow (CWE-121) within the Whois functionality. By inputting a 98-character buffer into the Domain Name field, an unauthenticated user can trigger an application crash.

Business impact

The vulnerability results in a denial of service condition for the affected iOS application. While the CVSS score of 7.5 indicates a high severity due to the impact on availability, the practical business impact is limited to the local disruption of the iNetTools application on the user's device.

Remediation

Immediate Action: Users should check the Apple App Store for the latest version of iNetTools and update the application if a patched version is available.

Proactive Monitoring: Security teams should monitor for unauthorized or unusual application behavior on managed mobile devices if these tools are deployed in a corporate environment.

Compensating Controls: Avoid using the Whois feature with untrusted or suspicious domain name inputs until the software has been updated to a secure version.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit Database (EDB-ID: 47716).

Analyst recommendation

Given the availability of a public proof-of-concept exploit, the risk of application disruption is credible. Organizations and individual users should prioritize updating the application to the latest available version to eliminate this vulnerability and restore stability to the Whois feature.

Sources

Originally found and disclosed by Ivan Marmolejo, per the CVE Program record.