CVE-2009-0858

EUVD-2009-0855
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
d.j.bernsteindjbdns
𝑥
≤ 1.05
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
djbdns
bookworm
1:1.05-15
fixed
bullseye
1:1.05-13+deb11u1
fixed
sid
1:1.05-16
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
djbdns
dapper
dne
gutsy
dne
hardy
dne
intrepid
ignored
jaunty
not-affected
karmic
not-affected