Description
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1831-1 | New djbdns packages fix privilege escalation |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:48:52.593Z
Reserved: 2009-03-09T00:00:00.000Z
Link: CVE-2009-0858
No data.
Status : Modified
Published: 2009-03-09T21:30:00.327
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-0858
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA