NULL pointer dereference in DNS library in Go - CVE-2018-17419
Published: June 4, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the setTA() function in scan_rr.go caused by the dns.ParseZone() parsing error. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Red Hat OpenShift Container Platform
How to mitigate CVE-2018-17419
Red Hat OpenShift Container Platform - addressed in versions 4.10.61, 4.11.42, 4.12.19, 4.13.1
External References
Related Security Bulletins
- Denial of service in Miek Gieben DNS library for Go
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.10