CVE Vulnerabilities

CVE-2009-1086

Published: Mar 25, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.

Affected Software 

Name Vendor Start Version End Version
Ldns Nlnetlabs 1.4.0 (including) 1.4.0 (including)
Ldns Nlnetlabs 1.4.1 (including) 1.4.1 (including)
Ldns Ubuntu hardy *
Ldns Ubuntu intrepid *
Ldns Ubuntu jaunty *
Ldns Ubuntu upstream *

References