CVE-2009-1755

NameCVE-2009-1755
DescriptionOff-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1803-1
Debian Bugs529418, 529420

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nsd (PTS)jessie4.1.0-3fixed
stretch4.1.14-1fixed
buster4.1.26-1fixed
bullseye4.3.5-1fixed
bookworm4.6.1-1fixed
sid, trixie4.11.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsdsourceetch2.3.6-1+etch1DSA-1803-1
nsdsourcelenny2.3.7-1.1+lenny1DSA-1803-1
nsdsource(unstable)2.3.7-3medium529420
nsd3sourcelenny3.0.7-3.lenny2DSA-1803-1
nsd3source(unstable)3.2.2-1medium529418

Notes

VU#710316

Search for package or bug name: Reporting problems