GHSA-369h-pjr2-6wrh
Dashboard / Vulnerabilities / GHSA-369h-pjr2-6wrh
GHSA-369h-pjr2-6wrh
Summary: Uncontrolled recursion in trust-dns-proto
Details: There's a stack overflow leading to a crash when Trust-DNS's parses a malicious DNS packet. Affected versions of this crate did not properly handle parsing of DNS message compression (RFC1035 section 4.1.4). The parser could be tricked into infinite loop when a compression offset pointed back to the same domain name to be parsed. This allows an attacker to craft a malicious DNS packet which when consumed with Trust-DNS could cause stack overflow and crash the affected software.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-20994, https://github.com/bluejekyll/trust-dns, https://rustsec.org/advisories/RUSTSEC-2018-0007.html
Affected packages
Package
Name: trust-dns-proto
Purl: pkg:cargo/trust-dns-proto
Affected ranges
Type: SEMVER
Events:
