CVE-2014-2032Improper Input Validation in Project Deadwood

Severity
5.9MEDIUMNVD
EPSS
1.6%
top 18.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 14

Description

Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDdeadwood_project/deadwood3.0.013.2.05+1
NVDmaradns_project/maradns2.0.052.0.09+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-q797-vg3x-r5qx: Deadwood before 22022-05-14

📋Vendor Advisories

1
Debian
CVE-2014-2032: maradns - Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 ...2014

💬Community

1
Bugzilla
CVE-2014-2031 CVE-2014-2032 maradns: DoS due to incorrect bounds checking on certain strings2014-02-18