CVE-2020-19860
Summary
| CVE | CVE-2020-19860 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-21 14:15:00 UTC |
| Updated | 2022-01-27 16:36:00 UTC |
| Description | When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| heap Out-of-bound Read vulnerability · Issue #50 · NLnetLabs/ldns · GitHub | MISC | github.com | |
| * bugfix #70: heap Out-of-bound Read vulnerability in · NLnetLabs/ldns@15d9620 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179054 Debian Security Update for ldns (DLA 2910-1)
- 198649 Ubuntu Security Notification for ldns Vulnerabilities (USN-5257-1)
- 354916 Amazon Linux Security Advisory for ldns : ALAS2-2023-2032
- 671580 EulerOS Security Update for ldns (EulerOS-SA-2022-1538)
- 671685 EulerOS Security Update for ldns (EulerOS-SA-2022-1737)
- 751778 OpenSUSE Security Update for ldns (openSUSE-SU-2022:0675-1)
- 751992 SUSE Enterprise Linux Security Update for ldns (SUSE-SU-2022:0675-1)