USN-7239-1: libmicrodns vulnerabilities
It was discovered that libmicrodns could recursively follow the same compression pointer, leading to an infinite loop. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6071) It was discovered that libmicrodns did not check the return value of the rrdecode function, which could lead to a double free. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-6072) It was discovered that libmicrodns incorrectly handled certain inputs, which could lead to an integer overflow. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6073) It was discovered that libmicrodns incorrectly handled certain inputs, which could lead to a out-of-bounds read. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6077) It was discovered that libmicrodns incorrectly handled memory when parsing mDNS messages in mdnsrecv, which could lead to a NULL pointer dereference. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6078) It was discovered that libmicrodns incorrectly handled memory, which could lead to excessive memory consumption due to memory leaks. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6079, CVE-2020-6080)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7239-1?
The severity of USN-7239-1 is classified as a denial of service vulnerability.
How do I fix USN-7239-1?
To fix USN-7239-1, you need to upgrade the libmicrodns0 package to version 0.0.8-1ubuntu0.1~esm1 or later.
Which versions of Ubuntu are affected by USN-7239-1?
Ubuntu 18.04 is the affected version for the USN-7239-1 vulnerability.
What vulnerability does USN-7239-1 address?
USN-7239-1 addresses a vulnerability that allows libmicrodns to enter an infinite loop by recursively following the same compression pointer.
Can exploitation of USN-7239-1 lead to system crashes?
Yes, an attacker could exploit USN-7239-1 to cause a denial of service, potentially leading to system crashes.