oss-security September 2011 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] CVE request: heap-based buffer over

[oss-security] CVE request: heap-based buffer overflow in ldns

From: Vincent Danen <vdanen_at_nospam>
Date: Sat Sep 24 2011 - 14:08:19 GMT
To: oss-security@lists.openwall.com

Could a CVE be assigned to this flaw? A boundary error in
ldns_rr_new_frm_str_internal() could lead to a heap-based buffer overfow
when processing RR records.

http://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=403
https://secunia.com/advisories/46153/
https://bugzilla.redhat.com/show_bug.cgi?id=741024

Thanks.

-- Vincent Danen / Red Hat Security Response Team