An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade adns | Jul 30, 2024 | Jun 18, 2020 |
| Freebsd | — | Upgrade adns | Aug 21, 2020 | Aug 20, 2020 |
| Suse | — | Upgrade libadns-develUpgrade libadns-devel-32bitUpgrade libadns1Upgrade adnsUpgrade libadns1-32bit | Jun 13, 2020 | Jun 12, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub