CVE Vulnerabilities

CVE-2020-24698

Double Free

Published: Oct 02, 2020 | Modified: Oct 08, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in PowerDNS Authoritative through 4.3.0 when –enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a crash or possibly arbitrary code execution. by sending crafted queries with a GSS-TSIG signature.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Authoritative Powerdns * 4.3.0 (including)
Pdns Ubuntu bionic *
Pdns Ubuntu groovy *
Pdns Ubuntu hirsute *
Pdns Ubuntu impish *
Pdns Ubuntu kinetic *
Pdns Ubuntu lunar *
Pdns Ubuntu mantic *
Pdns Ubuntu trusty *
Pdns Ubuntu xenial *

Potential Mitigations

References