Configuration error in Hesiod - CVE-2016-10152
Published: May 8, 2018
Vulnerability identifier: #VU12434
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10152
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The weakness exists in the read_config_file function in lib/hesiod. due to falling back to the ".athena.mit.edu" default domain when opening the configuration file fails. A remote attacker can poison the DNS cache and gain root privileges.
The weakness exists in the read_config_file function in lib/hesiod. due to falling back to the ".athena.mit.edu" default domain when opening the configuration file fails. A remote attacker can poison the DNS cache and gain root privileges.
Affected software
Hesiod
Gentoo Linux
Fedora
hesiod
Gentoo Linux
Fedora
hesiod
How to mitigate CVE-2016-10152
Install update from vendor's website.
hesiod - addressed in versions 3.2.1-14.fc27, 3.2.1-14.fc28, 3.2.1-14.fc29