trust-dns-server
Activity
- Latest release
- 2y ago
- Total releases
- 60
- Cadence
- ~29 days
- Last 12 months
- 0
Details
- License
- MIT OR Apache-2.0
- First release
- Dec 17, 2016
| Version | Released | |
|---|---|---|
0.23.2
unknown
|
0.23.2
unknown
Dependencies (25)
+ 17 more |
|
0.23.1
unknown
|
0.23.1
unknown
Dependencies (25)
+ 17 more |
|
0.23.0
unknown
|
0.23.0
unknown
Dependencies (25)
+ 17 more |
|
0.23.0-alpha.5
unknown
|
0.23.0-alpha.5
unknown
Dependencies (25)
+ 17 more |
|
0.23.0-alpha.4
unknown
|
0.23.0-alpha.4
unknown
Dependencies (24)
+ 16 more |
|
0.23.0-alpha.3
unknown
|
0.23.0-alpha.3
unknown
Dependencies (24)
+ 16 more |
|
0.22.1
unknown
|
0.22.1
unknown
Dependencies (25)
+ 17 more |
|
0.23.0-alpha.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.0-alpha.2
unknown
Dependencies (24)
+ 16 more |
|
0.22.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.22.0
unknown
Dependencies (25)
+ 17 more |
|
0.21.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.2
unknown
Dependencies (24)
+ 16 more |
|
0.21.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.1
unknown
Dependencies (24)
+ 16 more |
|
0.21.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0
unknown
Dependencies (24)
+ 16 more |
|
0.21.0-alpha.5
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0-alpha.5
unknown
Dependencies (24)
+ 16 more |
|
0.20.4
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.4
unknown
Dependencies (26)
+ 18 more |
|
0.21.0-alpha.4
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0-alpha.4
unknown
Dependencies (24)
+ 16 more |
|
0.21.0-alpha.3
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0-alpha.3
unknown
Dependencies (24)
+ 16 more |
|
0.21.0-alpha.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0-alpha.2
unknown
Dependencies (23)
+ 15 more |
|
0.21.0-alpha.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.21.0-alpha.1
unknown
Dependencies (23)
+ 15 more |
|
0.20.3
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.3
unknown
Dependencies (26)
+ 18 more |
|
0.20.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.2
unknown
Dependencies (26)
+ 18 more |
|
0.20.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.1
unknown
Dependencies (26)
+ 18 more |
|
0.19.7
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.7
unknown
Dependencies (25)
+ 17 more |
|
0.20.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0
unknown
Dependencies (26)
+ 18 more |
|
0.19.6
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.6
unknown
Dependencies (25)
+ 17 more |
|
0.20.0-alpha.3
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0-alpha.3
unknown
Dependencies (25)
+ 17 more |
|
0.20.0-alpha.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0-alpha.2
unknown
Dependencies (24)
+ 16 more |
|
0.20.0-alpha.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0-alpha.1
unknown
Dependencies (25)
+ 17 more |
|
0.19.5
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.5
unknown
Dependencies (25)
+ 17 more |
|
0.19.4
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.4
unknown
Dependencies (25)
+ 17 more |
|
0.19.3
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.3
unknown
Dependencies (25)
+ 17 more |
|
0.19.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.2
unknown
Dependencies (25)
+ 17 more |
|
0.19.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.1
unknown
Dependencies (25)
+ 17 more |
|
0.19.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.19.0
unknown
Dependencies (25)
+ 17 more |
|
0.18.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.18.1
unknown
Dependencies (24)
+ 16 more |
|
0.18.0
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.18.0
unknown
Dependencies (24)
+ 16 more |
|
0.18.0-alpha.3
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.18.0-alpha.3
unknown
Dependencies (24)
+ 16 more |
|
0.18.0-alpha.2
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.18.0-alpha.2
unknown
Dependencies (24)
+ 16 more |
|
0.18.0-alpha.1
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.18.0-alpha.1
unknown
Dependencies (28)
+ 20 more |
|
0.17.0
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.17.0
unknown
Dependencies (36)
+ 28 more |
|
0.16.1
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.16.1
unknown
Dependencies (36)
+ 28 more |
|
0.16.0
unknown
2 CVEs
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-35857
GHSA-4cww-f7w5-x525
RUSTSEC-2020-0001
Aug 25, 2021
Stack consumption in trust-dns-server
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
There's a stack overflow leading to a crash and potential DOS when processing additional records for return of MX or SRV record types from the server. This is only possible when a zone is configured with a null target for MX or SRV records. Prior to 0.16.0 the additional record processing was not supported by trust-dns-server. There Are no known issues with upgrading from 0.16 or 0.17 to 0.18.1. The remidy should be to upgrade to 0.18.1. If unable to do so, MX, SRV or other record types with a target to the null type, should be avoided. Fixed in
0.18.1
References
Updated Dec 08, 2023 · Source: OSV.dev |
0.16.0
unknown
Dependencies (36)
+ 28 more |
|
0.16.0-alpha.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.16.0-alpha.2
unknown
Dependencies (35)
+ 27 more |
|
0.15.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.15.1
unknown
Dependencies (35)
+ 27 more |
|
0.16.0-alpha.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.16.0-alpha.1
unknown
Dependencies (35)
+ 27 more |
|
0.15.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.15.0
unknown
Dependencies (34)
+ 26 more |
|
0.15.0-alpha.2
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.15.0-alpha.2
unknown
Dependencies (34)
+ 26 more |
|
0.15.0-alpha.1
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.15.0-alpha.1
unknown
Dependencies (26)
+ 18 more |
|
0.14.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.14.0
unknown
Dependencies (26)
+ 18 more |
|
0.13.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.13.0
unknown
Dependencies (20)
+ 12 more |
|
0.12.0
unknown
1 CVE
GHSA-5fm9-h728-fwpj
RUSTSEC-2023-0041
Jun 06, 2023
trust-dns vulnerable to Remote Attackers causing Denial-of-Service (packet loops) with crafted DNS packets
Medium
trust-dns and trust-dns-server are vulnerable to remotely triggered denial-of-service attacks, consuming both network and CPU resources.
DNS messages with the QR=1 bit set are responded to with a There are two scenarios how this can be exploited: 1) Create a loop between two instances of trust-dns, consuming network resources, or 2) consuming the CPU of a single instance. With two instances A and B an attacker sends a DNS query with a spoofed source IP address to A.
A replies with a A single server can get locked up replying to itself. Same setup as above, but now A sends the reply to itself. The packet is sent out as fast as the CPU and network stack manage. This locks up a CPU core. Multiple packets from the attacker consume multiple CPU cores. Fixed in
0.22.1
0.23.0-alpha.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.12.0
unknown
Dependencies (19)
+ 11 more |