CVE-2020-6073: Integer Overflow
An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be triggered, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libmicrodnsto a version that resolves this vulnerability.Fixed in 0.2.0-1 - Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.21-0+deb11u1Fixed in 3.0.21-0+deb12u1Fixed in 3.0.21-7
Event History
Frequently Asked Questions
What is CVE-2020-6073?
CVE-2020-6073 is a denial-of-service vulnerability in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0.
How severe is CVE-2020-6073?
CVE-2020-6073 has a severity rating of 7.5, which is considered high.
How does CVE-2020-6073 impact users?
CVE-2020-6073 can allow an attacker to trigger multiple integer overflows, leading to a denial of service.
What software is affected by CVE-2020-6073?
VLC version 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, and 3.0.19-1 are affected. Debian Linux version 9.0 is also affected.
How can CVE-2020-6073 be fixed?
To fix CVE-2020-6073, users should update to one of the recommended versions provided by the vendor.