VDB
Sign up
HIGH7.5

GHSA-369h-pjr2-6wrh

Uncontrolled recursion in trust-dns-proto

Details

There's a stack overflow leading to a crash when Trust-DNS's parses a malicious DNS packet. Affected versions of this crate did not properly handle parsing of DNS message compression (RFC1035 section 4.1.4). The parser could be tricked into infinite loop when a compression offset pointed back to the same domain name to be parsed. This allows an attacker to craft a malicious DNS packet which when consumed with Trust-DNS could cause stack overflow and crash the affected software.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/trust-dns-proto
Introduced in: 0Fixed in: 0.4.3

Upgrade trust-dns-proto to 0.4.3 or newer (ecosystem crates.io).

References