Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26265
HistoryAug 06, 2020 - 9:39 p.m.

Arbitrary Code Execution

2020-08-0621:39:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.006 Low

EPSS

Percentile

78.2%

pdns-recursor is vulnerable to arbitrary code execution. The vulnerability exists as an attacker (with enough privileges to change the system’s hostname) to cause disclosure of uninitialized memory content via a stack-based out-of-bounds read. It only occurs on systems where gethostname() does not have \0 termination of the returned string if the hostname is larger than the supplied buffer.