Heap-based Buffer Overflow in LDNS Affects Multiple Versions from NLnet Labs
CVE-2009-1086

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
25 March 2009

What is CVE-2009-1086?

A vulnerability exists in the ldns_rr_new_frm_str_internal function found in LDNS versions 1.4.x, which suffers from a heap-based buffer overflow. Attackers can exploit this flaw by crafting a DNS resource record (RR) featuring an excessively long class field or TTL field, potentially leading to memory corruption and triggering a denial of service condition. In some scenarios, this vulnerability may also allow for the execution of arbitrary code, thereby significantly jeopardizing the security of affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.