← Back to CVE List

CVE-2016-10152

Published: 2017-03-28T14:59Z
Last Modified: 2024-11-21T02:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt