OSV 1.4.0 · github-reviewed · 修改于 2023-06-14 06:25
发布时间
2021-08-26 04:43
GitHub 审查时间
2021-08-20 05:24
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/08/GHSA-369h-pjr2-6wrh/GHSA-369h-pjr2-6wrh.json
There's a stack overflow leading to a crash when Trust-DNS's parses a malicious DNS packet. Affected versions of this crate did not properly handle parsing of DNS message compression (RFC1035 section 4.1.4). The parser could be tricked into infinite loop when a compression offset pointed back to the same domain name to be parsed. This allows an attacker to craft a malicious DNS packet which when consumed with Trust-DNS could cause stack overflow and crash the affected software.