CVE-2018-17419

HIGH7.5EPSS 0.39%

miekg/dns parsing error leads to nil pointer dereference and DoS

Published: 5/18/2021Modified: 5/20/2024

Description

An issue was discovered in `setTA` in `scan_rr.go` in the Miek Gieben DNS library before 1.0.10 for Go. A `dns.ParseZone()` parsing error causes a segmentation violation, leading to denial of service.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)