Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-1755


Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.


Published

2009-05-22T11:52:40.547

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nlnetlabs nsd 2.0.0 Yes
Application nlnetlabs nsd 2.0.1 Yes
Application nlnetlabs nsd 2.0.2 Yes
Application nlnetlabs nsd 2.1.0 Yes
Application nlnetlabs nsd 2.1.1 Yes
Application nlnetlabs nsd 2.1.2 Yes
Application nlnetlabs nsd 2.1.3 Yes
Application nlnetlabs nsd 2.1.4 Yes
Application nlnetlabs nsd 2.1.5 Yes
Application nlnetlabs nsd 2.2.0 No
Application nlnetlabs nsd 2.2.1 No
Application nlnetlabs nsd 2.3.0 No
Application nlnetlabs nsd 2.3.2 No
Application nlnetlabs nsd 2.3.3 No
Application nlnetlabs nsd 2.3.4 No
Application nlnetlabs nsd 2.3.5 No
Application nlnetlabs nsd 2.3.6 No
Application nlnetlabs nsd 2.3.7 Yes
Application nlnetlabs nsd 3.0.0 No
Application nlnetlabs nsd 3.0.1 No
Application nlnetlabs nsd 3.0.2 No
Application nlnetlabs nsd 3.0.3 No
Application nlnetlabs nsd 3.0.4 No
Application nlnetlabs nsd 3.0.5 No
Application nlnetlabs nsd 3.0.6 No
Application nlnetlabs nsd 3.0.7 No
Application nlnetlabs nsd 3.0.8 No
Application nlnetlabs nsd 3.1.0 No
Application nlnetlabs nsd 3.1.1 No
Application nlnetlabs nsd 3.2.0 No
Application nlnetlabs nsd 3.2.1 Yes

References