Description
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1831-1 | New djbdns packages fix privilege escalation |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:48:52.593Z
Reserved: 2009-03-09T00:00:00.000Z
Link: CVE-2009-0858
No data.
Status : Deferred
Published: 2009-03-09T21:30:00.327
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-0858
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA