CVE-2009-1755
nsd nsd3 - denial of service
EPSS 3.2%
描述
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
如何修補 CVE-2009-1755
要修補 CVE-2009-1755,請將受影響套件升級到下列已修補版本。
- Debian/nsd—升級至 2.3.7-3 或更新版本
- Debian/nsd—升級至 2.3.6-1+etch1 或更新版本
- Debian/nsd3—升級至 3.0.7-3.lenny2 或更新版本
CVE-2009-1755 正在被利用嗎?
低 — EPSS 為 3.2%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2.3.7-3
- from 0, < 2.3.6-1+etch1
- from 0, < 3.0.7-3.lenny2