In the GNU project library developed for performing DNS queries, adns four of which are issues (, , , ) that can be exploited to perform remote code execution on the system. The other three vulnerabilities lead to denial of service through application crashes using adns.
The package includes a C library and a set of utilities for performing DNS queries in asynchronous mode or using an event-driven model. The issues have been resolved in releases . The vulnerabilities allow for the attack of applications calling adns functions through a specially crafted response or SOA/RP fields returned by a recursive DNS server.
Source: opennet.ru
