USN-7239-1

Source
https://ubuntu.com/security/notices/USN-7239-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7239-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7239-1
Related
Published
2025-01-28T23:36:20.655736Z
Modified
2025-01-28T23:36:20.655736Z
Summary
libmicrodns vulnerabilities
Details

It was discovered that libmicrodns could recursively follow the same compression pointer, leading to an infinite loop. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6071)

It was discovered that libmicrodns did not check the return value of the rr_decode function, which could lead to a double free. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-6072)

It was discovered that libmicrodns incorrectly handled certain inputs, which could lead to an integer overflow. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6073)

It was discovered that libmicrodns incorrectly handled certain inputs, which could lead to a out-of-bounds read. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6077)

It was discovered that libmicrodns incorrectly handled memory when parsing mDNS messages in mdns_recv, which could lead to a NULL pointer dereference. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6078)

It was discovered that libmicrodns incorrectly handled memory, which could lead to excessive memory consumption due to memory leaks. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-6079, CVE-2020-6080)

References

Affected packages

Ubuntu:Pro:18.04:LTS / libmicrodns

Package

Name
libmicrodns
Purl
pkg:deb/ubuntu/libmicrodns@0.0.8-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.8-1ubuntu0.1~esm1

Affected versions

0.*

0.0.7-2
0.0.8-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.0.8-1ubuntu0.1~esm1",
            "binary_name": "libmicrodns-dev"
        },
        {
            "binary_version": "0.0.8-1ubuntu0.1~esm1",
            "binary_name": "libmicrodns0"
        },
        {
            "binary_version": "0.0.8-1ubuntu0.1~esm1",
            "binary_name": "libmicrodns0-dbgsym"
        }
    ]
}