iodine - This is a piece of software that lets you tunnel IPv4 data through a DNS server. This can be usable in different situations where internet access is firewalled, but DNS queries are allowed.
A remote overflow exists in Iodine client.
Credit:
The information has been provided by poplix.
Vulnerable Systems:
* code.kryo.se Iodine version 0.3.2
* code.kryo.se Iodine version 0.3.3
The product fails to handle the 'handshake()' function during the handshakes from Iodine servers resulting in a stack-based buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
Successful exploitation may allow execution of arbitrary code.