CVE-2020-6072: Double Free
An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rrdecode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libmicrodnsto a version that resolves this vulnerability.Fixed in 0.2.0-1 - Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.21-0+deb11u1Fixed in 3.0.21-0+deb12u1Fixed in 3.0.21-7 - Upgrade
Upgrade
Videolabs libmicrodnsto a version that resolves this vulnerability.Fixed in 0.1.0
Event History
Frequently Asked Questions
What is CVE-2020-6072?
CVE-2020-6072 is an exploitable code execution vulnerability in the label-parsing functionality of Videolabs libmicrodns 0.1.0.
How severe is CVE-2020-6072?
CVE-2020-6072 is classified as critical with a severity score of 9.8.
Which software is affected by CVE-2020-6072?
CVE-2020-6072 affects Videolabs libmicrodns 0.1.0 and Debian Linux 9.0 with VLC versions 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, and 3.0.19-1.
How can CVE-2020-6072 be exploited?
CVE-2020-6072 can be exploited by parsing compressed labels in mDNS messages, which triggers a double free vulnerability that allows arbitrary code execution.
Where can I find more information about CVE-2020-6072?
For more information about CVE-2020-6072, you can refer to the following sources: - Talos Intelligence: [link1] - Debian Security Tracker: [link2] - Gentoo GLSA: [link3] [link1]: https://talosintelligence.com/vulnerability_reports/TALOS-2020-0995 [link2]: https://security-tracker.debian.org/tracker/CVE-2020-6072 [link3]: https://security.gentoo.org/glsa/202005-10