CVE-2016-10152
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-10152
Vendor advisory: cve@mitre.org — https://github.com/achernya/hesiod/pull/10
Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2017/01/21/1
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 3.2.1-3.1 |
| debian | bullseye | fixed | 3.2.1-3.1 |
| debian | forky | fixed | 3.2.1-3.1 |
| debian | sid | fixed | 3.2.1-3.1 |
| debian | trixie | fixed | 3.2.1-3.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hesiod_project | hesiod | {"endIncluding":"3.2.1"} | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.