CVE-2016-10152: Hesiod Project Hesiod
Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.
Affected products
- Hesiod Project Hesiod: up to and including 3.2.1
Published 2017-03-28. Last modified 2026-06-17.