CVE-2020-6077 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.
Group Package Affected Fixed Severity Status Ticket
AVG-1136 libmicrodns 0.1.0-1 0.1.2-1 Critical Fixed
Date Advisory Group Package Severity Type
30 Apr 2020 ASA-202004-24 AVG-1136 libmicrodns Critical multiple issues
References
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1000
https://github.com/videolabs/libmicrodns/commit/80860fad7e046959b730a0e37fd8d6ad955682ec