Novell Home

CVE-2009-1086

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2009-1086 at MITRE

Details

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.
Novell Bugzilla entry: 488631

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 11.1
  • unbound-debuginfo >= 1.0.0-2.21.1
  • unbound-debugsource >= 1.0.0-2.21.1
SAT Patch Nr: 840
openSUSE 11.1
  • unbound >= 1.0.0-2.21.1
  • unbound-devel >= 1.0.0-2.21.1
SAT Patch Nr: 840

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.