The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/90952 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1332493 | issue tracking |
http://www.openwall.com/lists/oss-security/2017/01/21/1 | mailing list third party advisory patch |
https://github.com/achernya/hesiod/pull/10 | issue tracking third party advisory patch |
https://security.gentoo.org/glsa/201805-01 | vendor advisory |