Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-19860
HistoryJan 21, 2022 - 12:00 a.m.

CVE-2020-19860

2022-01-2100:00:00
ubuntu.com
ubuntu.com
12
ldns version 1.7.1
zone file verification
heap vulnerability
information leakage
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.0%

When ldns version 1.7.1 verifies a zone file, the
ldns_rr_new_frm_str_internal function has a heap out of bounds read
vulnerability. An attacker can leak information on the heap by constructing
a zone file payload.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchldns< 1.7.0-3ubuntu4.1UNKNOWN
ubuntu20.04noarchldns< 1.7.0-4.1ubuntu1+esm1UNKNOWN
ubuntu22.04noarchldns< 1.7.1-2ubuntu4+esm1UNKNOWN
ubuntu16.04noarchldns< 1.6.17-8ubuntu0.1+esm1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.0%