Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Heap overflow and crash with crafted SVCB RR
Vulnerability Description
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
NLnet Labs NSD 缓冲区错误漏洞
Vulnerability Description
NLnet Labs NSD是荷兰NLnet Labs组织的一款DNS服务器软件。 NLnet Labs NSD 4.14.0版本至4.14.3之前版本存在安全漏洞,该漏洞源于在处理特制SVCB RR时,uint16_t变量在分配空间时发生整数溢出(总大小大于65535),导致堆溢出,攻击者可执行最多65509字节的受控头部写入。
CVSS Information
N/A
Vulnerability Type
N/A