5
CVSSv2

CVE-2009-1755

Published: 22/05/2009 Updated: 29/05/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

nlnetlabs nsd 2.0.1

nlnetlabs nsd 2.1.0

nlnetlabs nsd 2.1.2

nlnetlabs nsd 3.2.1

nlnetlabs nsd 2.3.7

nlnetlabs nsd 2.0.0

nlnetlabs nsd 2.1.3

nlnetlabs nsd 2.1.4

nlnetlabs nsd 2.1.5

nlnetlabs nsd 2.0.2

nlnetlabs nsd 2.1.1

Vendor Advisories

Ilja van Sprundel discovered that a buffer overflow in NSD, an authoritative name service daemon, allowed to crash the server by sending a crafted packet, creating a denial of service For the old stable distribution (etch), this problem has been fixed in version 236-1+etch1 of the nsd package For the stable distribution (lenny), this problem ha ...