CVE-2020-6071: High severity Videolabs libmicrodns vulnerability
An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libmicrodnsto a version that resolves this vulnerability.Fixed in 0.2.0-1 - Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.21-0+deb11u1Fixed in 3.0.21-0+deb12u1Fixed in 3.0.21-7 - Upgrade
Upgrade
Videolabs libmicrodnsto a version that resolves this vulnerability.Fixed in 0.1.0 - Compensating control
Mitigate the mDNS denial-of-service by restricting or filtering inbound mDNS traffic so attackers cannot send crafted mDNS messages to systems running Videolabs libmicrodns.
Event History
Frequently Asked Questions
What is CVE-2020-6071?
CVE-2020-6071 is a denial-of-service vulnerability in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0.
What is the severity of CVE-2020-6071?
The severity of CVE-2020-6071 is high with a severity value of 7.5.
How does CVE-2020-6071 affect me?
If you are using Videolabs libmicrodns 0.1.0, you may be vulnerable to a denial-of-service attack caused by the resource record-parsing functionality.
How do I fix CVE-2020-6071?
To fix CVE-2020-6071, you should update Videolabs libmicrodns to version 3.0.17.4-0+deb10u1 or later.
Where can I find more information about CVE-2020-6071?
You can find more information about CVE-2020-6071 on the following sources: [Talos Intelligence](https://talosintelligence.com/vulnerability_reports/TALOS-2020-0994), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2020-6071), [Gentoo GLSA](https://security.gentoo.org/glsa/202005-10)