Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-25583

In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when processing a DNSSL option, rtsold(8) decodes domain name labels per an encoding specified in RFC 1035 in which the first octet of each label contains the label's length. rtsold(8) did not validate label lengths correctly and could overflow the destination buffer.

  • Published: Mar 29, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-25583
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
freebsd / freebsd 11.3 11.3.x
freebsd / freebsd 11.3-p1 11.3-p1.x
freebsd / freebsd 11.3-p3 11.3-p3.x
freebsd / freebsd 11.3-p2 11.3-p2.x
freebsd / freebsd 12.1-p1 12.1-p1.x
freebsd / freebsd 12.1 12.1.x
freebsd / freebsd 11.3-p4 11.3-p4.x
freebsd / freebsd 11.3-p5 11.3-p5.x
freebsd / freebsd 11.3-p6 11.3-p6.x
freebsd / freebsd 12.1-p2 12.1-p2.x
freebsd / freebsd 11.3-p7 11.3-p7.x
freebsd / freebsd 12.1-p3 12.1-p3.x
freebsd / freebsd 12.1-p4 12.1-p4.x
freebsd / freebsd 11.3-p8 11.3-p8.x
freebsd / freebsd 11.4 11.4.x
freebsd / freebsd 12.1-p5 12.1-p5.x
freebsd / freebsd 11.3-p9 11.3-p9.x
freebsd / freebsd 12.1-p6 12.1-p6.x
freebsd / freebsd 11.3-p10 11.3-p10.x
freebsd / freebsd 11.3-p11 11.3-p11.x
freebsd / freebsd 11.4-p1 11.4-p1.x
freebsd / freebsd 12.1-p7 12.1-p7.x
freebsd / freebsd 12.1-p9 12.1-p9.x
freebsd / freebsd 12.1-p8 12.1-p8.x
freebsd / freebsd 11.4-p3 11.4-p3.x
freebsd / freebsd 11.4-p2 11.4-p2.x
freebsd / freebsd 11.3-p13 11.3-p13.x
freebsd / freebsd 11.3-p12 11.3-p12.x
freebsd / freebsd 12.2 12.2.x