Back to search
CVE-2011-0520
Published: Jan 28, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2011-0699
vdb-entry
x_refsource_VUPEN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610834
x_refsource_CONFIRM
[oss-security] 20110123 CVE request: MaraDNS DoS via long queries
mailing-list
x_refsource_MLIST
[oss-security] 20110124 Re: CVE request: MaraDNS DoS via long queries
mailing-list
x_refsource_MLIST
maradns-compressadddlabelpoints-bo(64885)
vdb-entry
x_refsource_XF
DSA-2196
vendor-advisory
x_refsource_DEBIAN
43107
third-party-advisory
x_refsource_SECUNIA
43027
third-party-advisory
x_refsource_SECUNIA
70630
vdb-entry
x_refsource_OSVDB
45966
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now