CVE-2009-0858
djbdns - privilege escalation
EPSS 6.3%
描述
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.
如何修補 CVE-2009-0858
要修補 CVE-2009-0858,請將受影響套件升級到下列已修補版本。
- Debian/djbdns—升級至 1:1.05-5 或更新版本
- Debian/djbdns—升級至 1:1.05-4+lenny1 或更新版本
CVE-2009-0858 正在被利用嗎?
中等 — EPSS 為 6.3%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1:1.05-5
- from 0, < 1:1.05-4+lenny1