When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-ldns | Mar 21, 2024 | Jan 21, 2022 | |
| Debian | debian-upgrade-ldns | Feb 7, 2022 | Jan 21, 2022 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-ldns | May 25, 2022 | Jan 21, 2022 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-ldns | Apr 26, 2022 | Jan 21, 2022 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-ldns | Apr 26, 2022 | Jan 21, 2022 | |
| Suse | — | suse-upgrade-ldnssuse-upgrade-ldns-develsuse-upgrade-libldns2suse-upgrade-perl-dns-ldnssuse-upgrade-python3-ldns | Mar 3, 2022 | Jan 21, 2022 |
| Ubuntu | ubuntu-pro-upgrade-libldns1ubuntu-pro-upgrade-libldns2ubuntu-pro-upgrade-libldns3ubuntu-upgrade-libldns2 | Feb 1, 2022 | Jan 21, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub