Heap Overflow Vulnerability in ldns 1.7.1 by NLnet Labs
CVE-2020-19861

7.5HIGH

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
21 January 2022

What is CVE-2020-19861?

The ldns library version 1.7.1 contains a vulnerability where the function ldns_nsec3_salt_data improperly trusts the length value from parsed zone files. This flaw permits a malicious actor to exploit the memcpy operation, resulting in the potential copying of excessive byte data. Consequently, this situation could lead to a heap overflow and may expose sensitive information from the affected system.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.