Candidate: CVE-2012-2978 PublicDate: 2012-07-27 10:27:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2978 http://security-tracker.debian.org/tracker/DSA-2515-1 Description: query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Marek VavruĊĦa and Lubos Slovak Assigned-to: CVSS: Patches_nsd3: upstream_nsd3: released (3.2.12-2) hardy_nsd3: ignored (reached end-of-life) lucid_nsd3: ignored (reached end-of-life) natty_nsd3: ignored (reached end-of-life) oneiric_nsd3: ignored (reached end-of-life) precise_nsd3: ignored (reached end-of-life) precise/esm_nsd3: DNE (precise was needed) quantal_nsd3: ignored (reached end-of-life) raring_nsd3: not-affected (3.2.12-2) saucy_nsd3: not-affected trusty_nsd3: DNE trusty/esm_nsd3: DNE utopic_nsd3: DNE vivid_nsd3: DNE vivid/stable-phone-overlay_nsd3: DNE vivid/ubuntu-core_nsd3: DNE wily_nsd3: DNE xenial_nsd3: DNE yakkety_nsd3: DNE zesty_nsd3: DNE devel_nsd3: DNE Patches_nsd: upstream_nsd: needs-triage hardy_nsd: ignored (reached end-of-life) lucid_nsd: ignored (reached end-of-life) natty_nsd: DNE oneiric_nsd: DNE precise_nsd: DNE precise/esm_nsd: DNE quantal_nsd: DNE raring_nsd: DNE saucy_nsd: DNE trusty_nsd: not-affected (4.0.0-5) trusty/esm_nsd: DNE (trusty was not-affected [4.0.0-5]) utopic_nsd: not-affected (4.0.0-5) vivid_nsd: not-affected (4.0.0-5) vivid/stable-phone-overlay_nsd: DNE vivid/ubuntu-core_nsd: DNE wily_nsd: not-affected (4.0.0-5) xenial_nsd: not-affected (4.0.0-5) yakkety_nsd: not-affected (4.0.0-5) zesty_nsd: not-affected (4.0.0-5) devel_nsd: not-affected (4.0.0-5)