HIGH🇬🇧 English

CVE-2023-39914

CVSS 7.5v3.1pub. 2023-09-13upd. 2024-11-21

NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Nlnetlabs Bcder

    APP
    Nlnetlabs
    < 0.7.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-33278CRITICAL9.1PL ✓ten sam vendor

Use-after-free w validatorze DNSSEC Unbound — RCE i DoS

CVE-2023-39916CRITICAL9.3PL ✓ten sam vendor

Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem

CVE-2019-25035CRITICAL9.8PL ✓ten sam vendor

Out-of-bounds write w Unbound przed wersją 1.9.5 (sldns_bget_token_par)

CVE-2019-25033CRITICAL9.8PL ✓ten sam vendor

Integer overflow w Unbound przed wersją 1.9.5 (makro ALIGN_UP)

CVE-2019-25032CRITICAL9.8PL ✓ten sam vendor

Integer overflow w alokatorze regionalnym Unbound DNS (przed wersją 1.9.5)