CVE-2017-9109
CRITICALadns < 1.5.2 - Heap-Based Buffer Overflow via Interleaved CNAME Answers
Title source: llmDescription
An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (on the heap) can be overrun. With this fixed, it prefers to look only at the answer RRs which come after the CNAME, which is at least arguably correct.
References (6)
Core 6
Core References
Third Party Advisory x_refsource_misc
http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=adns.git
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00037.html
Release Notes, Third Party Advisory x_refsource_confirm
https://www.chiark.greenend.org.uk/pipermail/adns-announce/2020/000004.html
Various Sources x_refsource_confirm
http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=adns.git%3Ba=blob%3Bf=changelog
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRVHN3GGVNQWAOL3PWC5FLAV7HUESLZR/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UGFZ4SPV6KFQK6ZNUZFB5Y32OYFOM5YJ/
Scores
CVSS v3
9.8
EPSS
0.0089
EPSS Percentile
75.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (4)
fedoraproject/fedora
31
fedoraproject/fedora
32
gnu/adns
< 1.5.2
opensuse/leap
15.1
Published
Jun 18, 2020
Tracked Since
Feb 18, 2026