An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Videolabs Subscribe
Libmicrodns Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4671-1 vlc security update
EUVD EUVD EUVD-2020-27231 An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
Ubuntu USN Ubuntu USN USN-7239-1 libmicrodns vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-08-04T08:47:40.911Z

Reserved: 2020-01-07T00:00:00

Link: CVE-2020-6077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-24T21:15:14.300

Modified: 2024-11-21T05:35:02.893

Link: CVE-2020-6077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses