CVE-2020-19861 describes a heap overflow vulnerability in ldns 1.7.1, specifically within the ldns_nsec3_salt_data function during zone file parsing. This flaw allows an attacker to cause information leakage by crafting a malicious zone file that leads to an overly trusted length value during a memcpy operation. Rated 7.5 HIGH on CVSS, this vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and primarily impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.1CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:1.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.