Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cww-f7w5-x525

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Stack consumption in trust-dns-server

There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided.

Пакеты

Наименование

trust-dns-server

rust
Затронутые версииВерсия исправления

>= 0.16.0, < 0.18.1

0.18.1

EPSS

Процентиль: 56%
0.00334
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.

EPSS

Процентиль: 56%
0.00334
Низкий

7.5 High

CVSS3

Дефекты

CWE-400