UBUNTU-CVE-2020-19861
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-19861
UBUNTU-CVE-2020-19861
Summary:
Details: When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.
References: https://ubuntu.com/security/CVE-2020-19861, https://github.com/NLnetLabs/ldns/issues/51, https://github.com/NLnetLabs/ldns/commit/136ec420437041fe13f344a2053e774f9050cc38, https://ubuntu.com/security/notices/USN-5257-1, https://ubuntu.com/security/notices/USN-5257-2, https://www.cve.org/CVERecord?id=CVE-2020-19861
Affected packages
Package
Name: ldns
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
