5
CVSSv2

CVE-2020-19861

Published: 21/01/2022 Updated: 05/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nlnetlabs ldns 1.7.1

Vendor Advisories

ldns could be made to expose sensitive information if it received a specially crafted input ...