CVE-2019-13952

Name
CVE-2019-13952
Description
The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv6 address in zone data.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/gdnsd/gdnsd/issues/185

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gdnsd:gdnsd:*:*:*:*:*:*:*:* gdnsd >= None < 2.4.3
cpe:2.3:a:gdnsd:gdnsd:*:*:*:*:*:*:*:* gdnsd >= 3.0.0 < 3.2.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gdnsd edge-community 2.4.3-r0 Timo Teräs <timo.teras@iki.fi> fixed
gdnsd 3.22-community 2.4.3-r0 None fixed
gdnsd 3.21-community 2.4.3-r0 None fixed
gdnsd 3.20-community 2.4.3-r0 None fixed
gdnsd 3.19-community 2.4.3-r0 None fixed
gdnsd 3.18-community 2.4.3-r0 None fixed
gdnsd 3.17-community 2.4.3-r0 None fixed