CVE-2009-1086 describes a heap-based buffer overflow in the ldns_rr_new_frm_str_internal function within ldns 1.4.x, affecting nlnetlabs ldns. This vulnerability allows remote attackers to trigger a denial of service through memory corruption and potentially execute arbitrary code by supplying a malformed DNS resource record with an excessively long class or TTL field. With a CVSS score of 6.4, it is considered medium severity, requiring no authentication and having low attack complexity, with potential impacts on integrity and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:1.4.0:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:1.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.