Heap Out of Bounds Read Vulnerability in ldns by NLnetLabs
CVE-2020-19860

6.5MEDIUM

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
21 January 2022

What is CVE-2020-19860?

A heap out of bounds read vulnerability exists in ldns version 1.7.1 due to the ldns_rr_new_frm_str_internal function failing to properly verify zone file inputs. An attacker can exploit this weakness by crafting a malicious zone file payload, potentially leading to the leakage of sensitive information stored in the heap memory. This vulnerability presents significant risks if exploited, underscoring the need for timely updates and verification of zone file integrity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.