When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ldns | Mar 21, 2024 | Jan 21, 2022 |
| Amazon Linux Ami 2 | — | Upgrade ldnsUpgrade ldns-pythonUpgrade ldns-docUpgrade ldns-develUpgrade ldns-debuginfo | May 3, 2023 | Jan 21, 2022 |
| Debian | — | Upgrade ldns | Feb 7, 2022 | Jan 21, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ldns | May 25, 2022 | Jan 21, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ldns | Apr 26, 2022 | Jan 21, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 21, 2022 |
| Suse | — | Upgrade perl-DNS-LDNSUpgrade python3-ldnsUpgrade libldns2Upgrade ldns-develUpgrade ldns | Mar 3, 2022 | Jan 21, 2022 |
| Ubuntu | — | Upgrade libldns2 (Ubuntu Pro)Upgrade libldns1 (Ubuntu Pro)Upgrade libldns2Upgrade libldns3 (Ubuntu Pro) | Feb 1, 2022 | Jan 21, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub