CVE-2019-13207

NameCVE-2019-13207
Descriptionnsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs931476

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nsd (PTS)jessie4.1.0-3vulnerable
stretch4.1.14-1vulnerable
buster4.1.26-1vulnerable
bullseye4.3.5-1fixed
bookworm4.6.1-1fixed
sid, trixie4.10.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsdsource(unstable)4.2.4-1low931476
nsd3sourcewheezy(unfixed)end-of-life
nsd3source(unstable)(unfixed)

Notes

[buster] - nsd <ignored> (Minor issue)
[stretch] - nsd <no-dsa> (Minor issue)
[jessie] - nsd <postponed> (Minor issue, crash on malformed admin-controlled disk configuration)
https://github.com/NLnetLabs/nsd/issues/20
https://github.com/NLnetLabs/nsd/commit/91102da24d5949ccfec8fdab5bae2d01c4cabab5

Search for package or bug name: Reporting problems