CVE-2016-10152
28.03.2017, 14:59
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.Enginsight
| Vendor | Product | Version |
|---|---|---|
| hesiod_project | hesiod | 𝑥 ≤ 3.2.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References