Remotely exploitable vulnerability in the GNU adns library

In the GNU project library developed for performing DNS queries, adns seven vulnerabilities have been identified four of which are issues (CVE-2017-9103, CVE-2017-9104, CVE-2017-9105, CVE-2017-9109) that can be exploited to perform remote code execution on the system. The other three vulnerabilities lead to denial of service through application crashes using adns.

The package adns includes a C library and a set of utilities for performing DNS queries in asynchronous mode or using an event-driven model. The issues have been resolved in releases 1.5.2 and 1.6.0. The vulnerabilities allow for the attack of applications calling adns functions through a specially crafted response or SOA/RP fields returned by a recursive DNS server.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster