CVE-2020-6072

🔴 Łataj teraz

Wykonanie kodu w libmicrodns umożliwia atakującemu zdalne wykonanie dowolnego kodu.

CVSS
9.8
EPSS
3.8%
Exploit
poc
Vendor
debian
Opis źródłowy (NVD)

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)3.8%
Opublikowano (NVD)2020-03-24 21:15:14 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:17:01 UTC
Referencje