CVE-2009-1755

NameCVE-2009-1755
DescriptionOff-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1803-1
NVD severitymedium (attack range: remote)
Debian Bugs529418, 529420

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nsd (PTS)jessie4.1.0-3fixed
stretch4.1.14-1fixed
buster, sid4.1.17-1fixed
nsd3 (PTS)wheezy3.2.12-3+deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsdsource(unstable)2.3.7-3medium529420
nsdsourceetch2.3.6-1+etch1mediumDSA-1803-1
nsdsourcelenny2.3.7-1.1+lenny1mediumDSA-1803-1
nsd3source(unstable)3.2.2-1medium529418
nsd3sourcelenny3.0.7-3.lenny2mediumDSA-1803-1

Notes

VU#710316

Search for package or bug name: Reporting problems