UBUNTU-CVE-2020-19860
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-19860
UBUNTU-CVE-2020-19860
Summary:
Details: When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
References: https://ubuntu.com/security/CVE-2020-19860, https://github.com/NLnetLabs/ldns/issues/50, https://github.com/NLnetLabs/ldns/commit/15d96206996bea969fbc918eb0a4a346f514b9f3, https://github.com/NLnetLabs/ldns/commit/4e9861576a600a5ecfa16ec2de853c90dd9ce276, https://ubuntu.com/security/notices/USN-5257-1, https://ubuntu.com/security/notices/USN-5257-2, https://www.cve.org/CVERecord?id=CVE-2020-19860
Affected packages
Package
Name: ldns
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
