CVE-2009-1086Out-of-bounds Write in Ldns

CWE-3994 documents4 sources
Severity
6.4MEDIUMNVD
EPSS
3.4%
top 12.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMay 2

Description

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

debiandebian/ldns< ldns 1.5.1-1 (bookworm)
Debiannlnetlabs/ldns< 1.5.1-1+3
NVDnlnetlabs/ldns1.4.0, 1.4.1+1

🔴Vulnerability Details

2
GHSA
GHSA-5957-cmgf-chq8: Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 12022-05-02
OSV
CVE-2009-1086: Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 12009-03-25

📋Vendor Advisories

1
Debian
CVE-2009-1086: ldns - Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns ...2009