GHSA-369h-pjr2-6wrh

    Dashboard / Vulnerabilities / GHSA-369h-pjr2-6wrh

    GHSA-369h-pjr2-6wrh

    Published: 25 Aug 2021Last Modified: 8 Nov 2023

    Summary: Uncontrolled recursion in trust-dns-proto

    Details: There's a stack overflow leading to a crash when Trust-DNS's parses a malicious DNS packet. Affected versions of this crate did not properly handle parsing of DNS message compression (RFC1035 section 4.1.4). The parser could be tricked into infinite loop when a compression offset pointed back to the same domain name to be parsed. This allows an attacker to craft a malicious DNS packet which when consumed with Trust-DNS could cause stack overflow and crash the affected software.

    Affected packages

    Package

    Name: trust-dns-proto

    Purl: pkg:cargo/trust-dns-proto

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High