Lucene search

K
freebsdFreeBSDE72FD82B-FA01-11D9-BC08-0001020EED82
HistoryJul 21, 2005 - 12:00 a.m.

dnrd -- remote buffer and stack overflow vulnerabilities

2005-07-2100:00:00
vuxml.freebsd.org
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.0%

Natanael Copa reports that dnrd is vulnerable to a remote
buffer overflow and a remote stack overflow. These
vulnerabilities can be triggered by sending invalid DNS
packets to dnrd.
The buffer overflow could potentially be used to execute
arbitrary code with the permissions of the dnrd daemon.
Note that dnrd runs in an chroot environment and runs as
non-root.
The stack overflow vulnerability can cause dnrd to
crash.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchdnrd< 2.19.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.0%

Related for E72FD82B-FA01-11D9-BC08-0001020EED82