CVE Vulnerabilities

CVE-2009-1086

Published: Mar 25, 2009 | Modified: May 15, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.

Affected Software

Name Vendor Start Version End Version
Ldns Nlnetlabs 1.4.0 (including) 1.4.0 (including)
Ldns Nlnetlabs 1.4.1 (including) 1.4.1 (including)
Ldns Ubuntu hardy *
Ldns Ubuntu intrepid *
Ldns Ubuntu jaunty *
Ldns Ubuntu upstream *

References