Description
rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for the issue.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- bluedragonsecurity / rldns= 1.3 – = 1.3
References
- VENDOR_ADVISORYhttps://github.com/bluedragonsecurity/rldns/security/advisories/GHSA-fv38-45j4-g9x4
- MISChttps://github.com/bluedragonsecurity/rldns-1.3-heap-out-of-bounds-vulnerability-fixed-in-rldns-1.4
- MISChttps://github.com/bluedragonsecurity/rldns_archives/blob/main/diff/rldns-1.4.diff
- MISChttps://medium.com/@w1sdom/heap-based-buffer-over-read-vulnerability-in-rldns-1-3-5da3bccdc031