• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2022-38177
  1. CVEs

CVE-2022-38177

high
  • Information
  • CPEs
  • Plugins

Description

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

References

https://kb.isc.org/docs/cve-2022-38177

http://www.openwall.com/lists/oss-security/2022/09/21/3

https://www.debian.org/security/2022/dsa-5235

https://lists.fedoraproject.org/archives/list/[email protected]/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/

https://lists.fedoraproject.org/archives/list/[email protected]/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/

https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html

https://security.gentoo.org/glsa/202210-25

https://security.netapp.com/advisory/ntap-20221228-0010/

Details

Source: MITRE

Published: 2022-09-21

Updated: 2023-02-28

Type: CWE-347

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance