DEBIAN-CVE-2009-0858

Source
https://security-tracker.debian.org/tracker/CVE-2009-0858
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0858.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2009-0858
Upstream
Downstream
Published
2009-03-09T21:30:00.327Z
Modified
2026-04-28T20:11:05.575684Z
Summary
[none]
Details

The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.

References

Affected packages

Debian:11 / djbdns

Package

Name
djbdns
Purl
pkg:deb/debian/djbdns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.05-5

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0858.json"

Debian:12 / djbdns

Package

Name
djbdns
Purl
pkg:deb/debian/djbdns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.05-5

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0858.json"

Debian:13 / djbdns

Package

Name
djbdns
Purl
pkg:deb/debian/djbdns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.05-5

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0858.json"

Debian:14 / djbdns

Package

Name
djbdns
Purl
pkg:deb/debian/djbdns?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.05-5

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0858.json"