CVE-2019-13207

NameCVE-2019-13207
Descriptionnsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh
Debian Bugs931476

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nsd (PTS)jessie4.1.0-3vulnerable
stretch4.1.14-1vulnerable
bullseye, sid, buster4.1.26-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsdsource(unstable)(unfixed)low931476
nsd3source(unstable)(unfixed)

Notes

[buster] - nsd <no-dsa> (Minor issue)
[stretch] - nsd <no-dsa> (Minor issue)
[jessie] - nsd <postponed> (Minor issue, crash on malformed admin-controlled disk configuration)
https://github.com/NLnetLabs/nsd/issues/20
https://github.com/NLnetLabs/nsd/commit/91102da24d5949ccfec8fdab5bae2d01c4cabab5

Search for package or bug name: Reporting problems