Resource exhaustion in libmicrodns - CVE-2020-6079
Published: March 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to encountering errors while parsing mDNS messages in the "rr_decode" function in the resource allocation handling. A remote attacker can send mDNS messages, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
vlc (Debian package)
vlc (Alpine package)
libmicrodns0 (Ubuntu package)
VLC Media Player
How to mitigate CVE-2020-6079
vlc (Debian package) - update to 3.0.10-0+deb9u1
VLC Media Player - update to 3.0.9.2
vlc (Alpine package) - update to 3.0.9.2-r0
libmicrodns0 (Ubuntu package) - update to Ubuntu Pro