Unrated severityNVD Advisory· Published Mar 24, 2020· Updated Aug 4, 2024
CVE-2020-6072
CVE-2020-6072
Description
An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- security.gentoo.org/glsa/202005-10mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2020/dsa-4671mitrevendor-advisoryx_refsource_DEBIAN
- talosintelligence.com/vulnerability_reports/TALOS-2020-0995mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.