CVE-2020-19860 describes a heap out-of-bounds read vulnerability in ldns version 1.7.1, specifically within the ldns_rr_new_frm_str_internal function when verifying zone files. This flaw allows an unauthenticated attacker to leak heap information by crafting a malicious zone file. Rated with a CVSS score of 6.5 (Medium), the vulnerability has low attack complexity but high confidentiality impact, though it requires user interaction. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.1CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:1.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.