CVE-2011-3581 describes a heap-based buffer overflow in the ldns_rr_new_frm_str_internal function of ldns versions prior to 1.6.11. This vulnerability allows remote attackers to trigger a denial of service or potentially execute arbitrary code by supplying a malformed Resource Record (RR) with an unknown type and excessive length. With a CVSS score of 6.8, it is considered medium severity, requiring moderate attack complexity but potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.10CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:*:*:*:*:*:*:*:* | ||
0.50CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:0.50:*:*:*:*:*:*:* | ||
0.60CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:0.60:*:*:*:*:*:*:* | ||
0.65CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:0.65:*:*:*:*:*:*:* | ||
0.66CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:ldns:0.66:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.