Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2020-19860
HistoryJan 21, 2022 - 2:15 p.m.

CVE-2020-19860

2022-01-2114:15:00
Alpine Linux Development Team
security.alpinelinux.org
11
ldns version 1.7.1
heap out of bounds
zone file
vulnerability
unix

EPSS

0.002

Percentile

52.0%

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

OSVersionArchitecturePackageVersionFilename
Alpine3.14-mainnoarchldns= 1.7.1-r1UNKNOWN
Alpine3.13-mainnoarchldns= 1.7.1-r1UNKNOWN
Alpine3.12-mainnoarchldns= 1.7.1-r1UNKNOWN