Possible buffer overread from reading DNS responses
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.9epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Zabbix · ZabbixReferences
https://lists.debian.org/debian-lts-announce/2024/01/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/10/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BYSYLA7VTHR25CBLYO5ZLEJFGU7HTHQB/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UMFKNV5E4LG2DIZNPRWQ2ENH75H6UEQT/https://support.zabbix.com/browse/ZBX-23855