CVE-2016-10152
28.03.2017, 14:59
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.Enginsight
Vendor | Product | Version |
---|---|---|
hesiod_project | hesiod | 𝑥 ≤ 3.2.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References