CVE-2011-3581

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) with an unknown type containing input that is longer than a specified length.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
nlnetlabsldns
𝑥
≤ 1.6.10
nlnetlabsldns
0.50
nlnetlabsldns
0.60
nlnetlabsldns
0.65
nlnetlabsldns
0.66
nlnetlabsldns
0.70
nlnetlabsldns
1.0.0
nlnetlabsldns
1.1.0
nlnetlabsldns
1.2.0
nlnetlabsldns
1.2.1
nlnetlabsldns
1.2.2
nlnetlabsldns
1.3
nlnetlabsldns
1.4.0
nlnetlabsldns
1.4.1
nlnetlabsldns
1.5.0
nlnetlabsldns
1.5.1
nlnetlabsldns
1.6.0
nlnetlabsldns
1.6.1
nlnetlabsldns
1.6.2
nlnetlabsldns
1.6.3
nlnetlabsldns
1.6.4
nlnetlabsldns
1.6.5
nlnetlabsldns
1.6.6
nlnetlabsldns
1.6.7
nlnetlabsldns
1.6.8
nlnetlabsldns
1.6.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ldns
bullseye
1.7.1-2
fixed
bookworm
1.8.3-1
fixed
sid
1.8.4-1
fixed
trixie
1.8.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ldns
trusty
dne
saucy
not-affected
raring
ignored
quantal
not-affected
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored