The setipv6() function in zscanrfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv6 address in zone data.
{ "binaries": [ { "binary_version": "2.2.0-1ubuntu1", "binary_name": "gdnsd" }, { "binary_version": "2.2.0-1ubuntu1", "binary_name": "gdnsd-dev" } ] }
{ "binaries": [ { "binary_version": "2.3.0-1", "binary_name": "gdnsd" }, { "binary_version": "2.3.0-1", "binary_name": "gdnsd-dev" } ] }
{ "binaries": [ { "binary_version": "2.4.2-1", "binary_name": "gdnsd" }, { "binary_version": "2.4.2-1", "binary_name": "gdnsd-dev" } ] }