NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNlnetlabs Bcder
APPNlnetlabs< 0.7.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2026-33278CRITICAL9.1PL ✓ten sam vendor
Use-after-free w validatorze DNSSEC Unbound — RCE i DoS
CVE-2023-39916CRITICAL9.3PL ✓ten sam vendor
Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem
CVE-2019-25035CRITICAL9.8PL ✓ten sam vendor
Out-of-bounds write w Unbound przed wersją 1.9.5 (sldns_bget_token_par)
CVE-2019-25033CRITICAL9.8PL ✓ten sam vendor
Integer overflow w Unbound przed wersją 1.9.5 (makro ALIGN_UP)
CVE-2019-25032CRITICAL9.8PL ✓ten sam vendor
Integer overflow w alokatorze regionalnym Unbound DNS (przed wersją 1.9.5)