668
VMScore

CVE-2020-6072

Published: 24/03/2020 Updated: 03/06/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolabs libmicrodns 0.1.0

debian debian linux 9.0

Vendor Advisories

Multiple security issues were discovered in the microdns plugin of the VLC media player, which could result in denial of service or potentially the execution of arbitrary code via malicious mDNS packets For the oldstable distribution (stretch), these problems have been fixed in version 3010-0+deb9u1 This update disables the microdns plugin For ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1136 libmicrodns 010-1 Medium Vulnerable ...