10

CVE-2016-10152

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hesiod ProjectHesiod Version <= 3.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.83% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2017/01/21/1
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/90952
Third Party Advisory
VDB Entry
https://security.gentoo.org/glsa/201805-01
https://bugzilla.redhat.com/show_bug.cgi?id=1332493
Issue Tracking
https://github.com/achernya/hesiod/pull/10
Patch
Third Party Advisory
Issue Tracking