Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-19860

Опубликовано: 21 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

A heap out-of-bounds read flaw was found in ldns, specifically within the ldns_rr_new_frm_str_internal function. This flaw allows an attacker to leak information on the heap by creating a malicious zone file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ldnsOut of support scope
Red Hat Enterprise Linux 7ldnsOut of support scope
Red Hat Enterprise Linux 8ldnsWill not fix
Red Hat Enterprise Linux 9ldnsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2044427ldns: heap overread vulnerability via zone file

EPSS

Процентиль: 69%
0.0131
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

CVSS3: 6.5
nvd
больше 4 лет назад

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

CVSS3: 6.5
debian
больше 4 лет назад

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_ ...

github
больше 4 лет назад

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость функции ldns_rr_new_frm_str_internal библиотеки DNS LDNS, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 69%
0.0131
Низкий

6.5 Medium

CVSS3