VYPR

rtsold

by FreeBSD

CVEs (4)

  • CVE-2020-25583CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when processing a DNSSL option, rtsold(8) decodes domain name labels per an encoding specified in RFC 1035 in which the first octet of…

  • CVE-2020-25577CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(8) does not verify that the RDNSS option does not extend past the end of the received packet before processing its contents. While…

  • CVE-2025-14558HigMar 9, 2026
    risk 0.50cvss 7.2epss 0.06

    The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that…

  • CVE-2014-3954Oct 27, 2014
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.