CVE-2020-6071 PUBLISHED

An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

EPSS 0.31% · 54.3th percentile

Risk Scores

EPSS Score
0.31%
54.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSvlc3.0.8-0ubuntu18.04.1+esm2, 3.0.7.1-0ubuntu18.04.1, 3.0.8-0ubuntu18.04.1
Ubuntu:Pro:18.04:LTSlibmicrodns0.0.7-2, 0.0.8-1, 0

Timeline

References

Open in Interactive Console →