Resource exhaustion in libmicrodns - CVE-2020-6080
Published: March 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to encountering errors while parsing mDNS messages in the "rr_read_TXT" function in the resource allocation handling. A remote attacker can send mDNS messages, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
vlc (Debian package)
libmicrodns0 (Ubuntu package)
How to mitigate CVE-2020-6080
vlc (Debian package) - update to 3.0.10-0+deb9u1
libmicrodns0 (Ubuntu package) - update to Ubuntu Pro