Vulnerability Report: GO-2020-0028
- CVE-2018-17419, GHSA-9jcx-pr2f-qvq5
- Affects: github.com/miekg/dns
- Published: Apr 14, 2021
- Modified: May 20, 2024
Due to a nil pointer dereference, parsing a malformed zone file containing TA records may cause a panic. If parsing user supplied input, this may be used as a denial of service vector.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.10
Aliases
References
- https://github.com/miekg/dns/commit/501e858f679edecd4a38a86317ce50271014a80d
- https://github.com/miekg/dns/issues/742
- https://vuln.go.dev/ID/GO-2020-0028.json
Credits
- @tr3ee
Feedback
See anything missing or incorrect?
Suggest an edit to this report.