VDB

CVE-2020-6079

CVE-2020-6079 PUBLISHED

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through decoding of the domain name performed by rr_decode.

EPSS 0.62% · 70.5th percentile

Risk Scores

EPSS Score
0.62%
70.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSvlc2.2.6-6, 2.2.6-6build1, 2.2.7-1
Ubuntu:Pro:18.04:LTSlibmicrodns0, 0.0.7-2, 0.0.8-1

Timeline

  • Mar 24, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›