SB2018101110 - Double Free in ldns (Alpine package)
Published: October 11, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double Free (CVE-ID: CVE-2017-1000231)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=16b7234d95adf0e83952001d0348d83a134e461e
- https://git.alpinelinux.org/aports/commit/?id=8375eecad3cde88418634fab3d5bd7169b420b72
- https://git.alpinelinux.org/aports/commit/?id=8de6bcd239711020a3bafdfa9195ff703b6a84be
- https://git.alpinelinux.org/aports/commit/?id=f7f3b355b2e9c3f5ef29fe317425f380fbacc5d0