CVE-2020-6073 is a high-severity denial-of-service vulnerability affecting Videolabs libmicrodns 0.1.0 and Debian-based systems utilizing it. The flaw resides in the TXT record-parsing functionality, where multiple integer overflows can be triggered by specially crafted mDNS messages. This allows an unauthenticated attacker to remotely cause a denial of service (CVSS 7.5). The vulnerability has no known public exploits or Metasploit modules, and it is not listed on the CISA KEV catalog. While there is limited community discussion and media coverage, indicating low current attention, the potential for a remote denial-of-service attack warrants patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:videolabs:libmicrodns:0.1.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.