Heap-based Buffer Overflow in LDNS by NLnet Labs
CVE-2011-3581

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
4 November 2011

What is CVE-2011-3581?

A heap-based buffer overflow vulnerability exists in the ldns_rr_new_frm_str_internal function of LDNS prior to version 1.6.11. This flaw allows remote attackers to craft a Resource Record (RR) with an oversized input, potentially leading to a denial of service through application crashes and, in some conditions, the execution of arbitrary code.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.