CVE Vulnerabilities

CVE-2020-6080

Missing Release of Memory after Effective Lifetime

Published: Mar 24, 2020 | Modified: Apr 22, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through the function rr_read_RR [5] reads the current resource record, except for the RDATA section. This is read by the loop at in rr_read. For each RR type, a different function is called. When the RR type is 0x10, the function rr_read_TXT is called at [6].

Weakness

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.

Affected Software

Name Vendor Start Version End Version
Libmicrodns Videolabs 0.1.0 (including) 0.1.0 (including)
Libmicrodns Ubuntu bionic *
Libmicrodns Ubuntu eoan *
Libmicrodns Ubuntu trusty *
Libmicrodns Ubuntu upstream *
Vlc Ubuntu bionic *
Vlc Ubuntu groovy *
Vlc Ubuntu hirsute *
Vlc Ubuntu impish *
Vlc Ubuntu kinetic *
Vlc Ubuntu lunar *
Vlc Ubuntu mantic *
Vlc Ubuntu trusty *
Vlc Ubuntu xenial *

Potential Mitigations

  • Choose a language or tool that provides automatic memory management, or makes manual memory management less error-prone.
  • For example, glibc in Linux provides protection against free of invalid pointers.
  • When using Xcode to target OS X or iOS, enable automatic reference counting (ARC) [REF-391].
  • To help correctly and consistently manage memory when programming in C++, consider using a smart pointer class such as std::auto_ptr (defined by ISO/IEC ISO/IEC 14882:2003), std::shared_ptr and std::unique_ptr (specified by an upcoming revision of the C++ standard, informally referred to as C++ 1x), or equivalent solutions such as Boost.

References