CVE-2010-2444Maradns vulnerability

5 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 33.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateMay 17

Description

parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/maradns< maradns 1.4.03-1 (bullseye)
Debianmaradns/maradns< 1.4.03-1
NVDmaradns/maradns22 versions+21

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xr2r-4cvv-wp49: parse/Csv2_parse2022-05-17
OSV
CVE-2010-2444: parse/Csv2_parse2010-06-25

📋Vendor Advisories

1
Debian
CVE-2010-2444: maradns - parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not...2010

💬Community

1
Bugzilla
CVE-2010-2444 MaraDNS: DoS (NULL pointer dereference) via specially-crafted csv2 zone file2010-06-28
CVE-2010-2444 — Debian Maradns vulnerability | cvebase