{"id":"CVE-2009-1086","details":"Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.","modified":"2026-04-10T03:40:41.466070Z","published":"2009-03-25T18:30:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/35013"},{"type":"ADVISORY","url":"http://secunia.com/advisories/35065"},{"type":"ADVISORY","url":"http://www.debian.org/security/2009/dsa-1795"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html"},{"type":"WEB","url":"http://www.nlnetlabs.nl/bugs/show_bug.cgi?id=232"},{"type":"WEB","url":"http://www.nlnetlabs.nl/svn/ldns/tags/release-1.5.0/Changelog"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2009/03/24/4"},{"type":"WEB","url":"http://www.securityfocus.com/bid/34233"}],"schema_version":"1.7.5"}