CVE-2012-2978
published 2012-07-27CVE-2012-2978: query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
9.23%
94.7th percentile
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | — | — |
| nlnetlabs | nsd | >= 0 < 4.0.0-5 | 4.0.0-5 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wgh7-q8c2-58gg: query
ghsa_unreviewed·2022-05-17
CVE-2012-2978 [MEDIUM] CWE-119 GHSA-wgh7-q8c2-58gg: query
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
OSV
CVE-2012-2978: query
osv·2012-07-27·CVSS 5.0
CVE-2012-2978 [MEDIUM] CVE-2012-2978: query
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
No detection rules found.
No public exploits indexed.
http://osvdb.org/84097http://secunia.com/advisories/49795http://secunia.com/advisories/49997http://www.debian.org/security/2012/dsa-2515http://www.kb.cert.org/vuls/id/624931http://www.nlnetlabs.nl/downloads/CVE-2012-2978.txthttp://www.securityfocus.com/bid/54606http://osvdb.org/84097http://secunia.com/advisories/49795http://secunia.com/advisories/49997http://www.debian.org/security/2012/dsa-2515http://www.kb.cert.org/vuls/id/624931http://www.nlnetlabs.nl/downloads/CVE-2012-2978.txthttp://www.securityfocus.com/bid/54606
2012-07-27
Published