5.8

CVE-2009-0858

Exploit
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
D.J.BernsteinDjbdns Version <= 1.05
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.28% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://it.slashdot.org/article.pl?sid=09/03/05/2014249
http://marc.info/?l=djbdns&m=123554945710038
http://marc.info/?l=djbdns&m=123613000920446&w=2
http://secunia.com/advisories/35820
http://securityandthe.net/2009/03/05/security-issue-in-djbdns-confirmed/
Patch
http://www.debian.org/security/2009/dsa-1831
http://www.securityfocus.com/archive/1/501294/100/0/threaded
http://www.securityfocus.com/archive/1/501340/100/0/threaded
http://www.securityfocus.com/archive/1/501479/100/0/threaded
http://www.securityfocus.com/bid/33937
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/49003