CVE-2020-6079 PUBLISHED

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through decoding of the domain name performed by rr_decode.

EPSS 0.31% · 54.1th percentile

Risk Scores

EPSS Score
0.31%
54.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSvlc3.0.8-0ubuntu18.04.1+esm2, 3.0.7.1-0ubuntu18.04.1, 3.0.8-0ubuntu18.04.1
Ubuntu:Pro:18.04:LTSlibmicrodns0.0.7-2, 0.0.8-1, 0

Timeline

References

Open in Interactive Console →