CVE-2011-0520
maradns - buffer overflow
EPSS 5.2%
描述
The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow.
如何修補 CVE-2011-0520
要修補 CVE-2011-0520,請將受影響套件升級到下列已修補版本。
- Debian/maradns—升級至 1.4.03-1.1 或更新版本
- Debian/maradns—升級至 1.3.07.09-2.1 或更新版本
CVE-2011-0520 正在被利用嗎?
中等 — EPSS 為 5.2%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1.4.03-1.1
- from 0, < 1.3.07.09-2.1