PT-2020-2148 · Videolabs+1 · Libmicrodns+1

Published

2020-03-24

·

Updated

2025-01-28

·

CVE-2020-6079

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Videolabs libmicrodns version 0.1.0
Description The issue is related to a denial-of-service condition that can occur due to improper resource allocation handling when parsing mDNS messages. If errors are encountered during this process, some allocated data may not be freed, potentially leading to resource exhaustion. An attacker can exploit this by repeatedly sending a specially crafted mDNS message, triggering the vulnerability through the decoding of the domain name performed by rr decode. This can result in a denial-of-service condition or potentially allow for remote code execution.
Recommendations For Videolabs libmicrodns version 0.1.0, consider restricting access to the rr decode function to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the domain name decoding feature in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Leak

Buffer Overflow

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2020-02052
CVE-2020-6079
DSA-4671-1
MGASA-2020-0203
USN-7239-1

Affected Products

Ubuntu
Libmicrodns