HIGH
An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0
Published Mar 24, 2020
7.5
HIGHCVSS 3.1
EPSS 3.15%
Description
An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through decoding of the domain name performed by rr_decode.
Affected products
- Vendor n/a Product Videolabs Defaultn/a
- Version Videolabs libmicrodns 0.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Videolabs | n/a |
|
Configuration 1
- 0.1.0
Configuration 2
OR
- 9.0
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://security.gentoo.org/glsa/202005-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1002 x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://www.debian.org/security/2020/dsa-4671 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://security.gentoo.org/glsa/202005-10 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1002 | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://www.debian.org/security/2020/dsa-4671 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Mar 24, 2020
Updated Aug 4, 2024
Reserved Jan 7, 2020
Link CVE-2020-6079
CISA Vulnrichment
Updated n/a