CVE-2016-10152

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
10
HIGH
Affected
1
PROJECT

Description

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

Hesiod name service library
GitHubGitHub
21