CVE-2020-6077: High severity Videolabs libmicrodns vulnerability
An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libmicrodnsto a version that resolves this vulnerability.Fixed in 0.2.0-1 - Upgrade
Upgrade
debian/vlcto a version that resolves this vulnerability.Fixed in 3.0.21-0+deb11u1Fixed in 3.0.21-0+deb12u1Fixed in 3.0.21-7 - Upgrade
Upgrade
Videolabs libmicrodnsto a version that resolves this vulnerability.Fixed in 0.1.0
Event History
Frequently Asked Questions
What is CVE-2020-6077?
CVE-2020-6077 is a denial-of-service vulnerability found in the message-parsing functionality of Videolabs libmicrodns 0.1.0.
How severe is CVE-2020-6077?
CVE-2020-6077 has a severity rating of 7.5 (high).
How does CVE-2020-6077 affect the affected software?
CVE-2020-6077 affects the affected software by causing a denial-of-service condition.
Which versions of the affected software are vulnerable?
Versions 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, and 3.0.19-1 of the Debian VLC package, as well as version 0.1.0 of Videolabs libmicrodns, are vulnerable to CVE-2020-6077.
How can I fix CVE-2020-6077?
To fix CVE-2020-6077, users should update to the latest versions of the affected software, which have the necessary security patches.