ZeroHour

CVE-2016-10152

CVSS 3.0
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

Vendors
hesiod project
Products
hesiod
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.