An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution.
References
Link | Resource |
---|---|
http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=adns.git;a=blob;f=changelog | Release Notes |
https://www.chiark.greenend.org.uk/pipermail/adns-announce/2020/000004.html | Release Notes Third Party Advisory |
http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=adns.git | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRVHN3GGVNQWAOL3PWC5FLAV7HUESLZR/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UGFZ4SPV6KFQK6ZNUZFB5Y32OYFOM5YJ/ | Mailing List Third Party Advisory |
Information
Published : 2020-06-18 07:15
Updated : 2023-01-27 11:00
NVD link : CVE-2017-9105
Mitre link : CVE-2017-9105
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
gnu
- adns
fedoraproject
- fedora