Unchecked Return Value in libmicrodns - CVE-2020-6078
Published: March 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists within the message-parsing functionality due to the "mdns_read_header" function is not checked when parsing mDNS messages in "mdns_recv". A remote attacker can send a specially crafted mDNS message and cause a denial of service condition on the target system.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
vlc (Debian package)
vlc (Alpine package)
libmicrodns0 (Ubuntu package)
VLC Media Player
How to mitigate CVE-2020-6078
vlc (Debian package) - update to 3.0.10-0+deb9u1
VLC Media Player - update to 3.0.9.2
vlc (Alpine package) - update to 3.0.9.2-r0
libmicrodns0 (Ubuntu package) - update to Ubuntu Pro