Debian Maradns vulnerabilities

15 known vulnerabilities affecting debian/maradns.

Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM5LOW6

Vulnerabilities

Page 1 of 1
CVE-2023-31137HIGHCVSS 7.5fixed in maradns 2.0.13-1.4+deb11u1 (bullseye)2023
CVE-2023-31137 [HIGH] CVE-2023-31137: maradns - MaraDNS is open-source software that implements the Domain Name System (DNS). In... MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability exists in the `decomp_get_rddata` function within
debian
CVE-2022-30256HIGHCVSS 7.5fixed in maradns 2.0.13-1.4+deb11u1 (bullseye)2022
CVE-2022-30256 [HIGH] CVE-2022-30256: maradns - An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant... An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS speci
debian
CVE-2014-2031LOWCVSS 5.92014
CVE-2014-2031 [MEDIUM] CVE-2014-2031: maradns - Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 ... Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error. Scope: local bullseye: resolved
debian
CVE-2014-2032LOWCVSS 5.92014
CVE-2014-2032 [MEDIUM] CVE-2014-2032: maradns - Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 ... Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation. Scope: local bullseye: resolved
debian
CVE-2012-0024HIGHCVSS 7.8fixed in maradns 1.4.09-1 (bullseye)2012
CVE-2012-0024 [HIGH] CVE-2012-0024: maradns - MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS da... MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. Scope: local bullseye: resolved (fixed in 1.4.09-1)
debian
CVE-2012-1570MEDIUMCVSS 4.3fixed in maradns 1.4.12-1 (bullseye)2012
CVE-2012-1570 [MEDIUM] CVE-2012-1570: maradns - The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cac... The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. Scope: local bullseye: resolved (fixed in 1.4.12-1)
debian
CVE-2011-0520HIGHCVSS 7.5fixed in maradns 1.4.03-1.1 (bullseye)2011
CVE-2011-0520 [HIGH] CVE-2011-0520: maradns - The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4... The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow. Scope: local bullseye: resolved (fixed in 1.4.0
debian
CVE-2011-5056LOWCVSS 2.12011
CVE-2011-5056 [LOW] CVE-2011-5056: maradns - The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS ... The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted records in zone files, a different vulnerability than CVE-2012-0024. Scope: local bullseye: resolved
debian
CVE-2011-5055LOWCVSS 5.0fixed in maradns 1.4.09-1 (bullseye)2011
CVE-2011-5055 [MEDIUM] CVE-2011-5055: maradns - MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly ... MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. NOTE: this issue exists because of an incomplete fix for CVE-2012-0024. Sc
debian
CVE-2010-2444LOWCVSS 4.3fixed in maradns 1.4.03-1 (bullseye)2010
CVE-2010-2444 [MEDIUM] CVE-2010-2444: maradns - parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not... parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file. Scope: local bullseye: resolved (fixed in 1.4.03-1)
debian
CVE-2008-0061MEDIUMCVSS 5.0fixed in maradns 1.2.12.08-1 (bullseye)2008
CVE-2008-0061 [MEDIUM] CVE-2008-0061: maradns - MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows... MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records." Scope: local bullseye: resolved (fixed in 1.2.12.08-1)
debian
CVE-2007-3114MEDIUMCVSS 5.0fixed in maradns 1.2.12.05-1 (bullseye)2007
CVE-2007-3114 [MEDIUM] CVE-2007-3114: maradns - Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.... Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3115 and CVE-2007-3116. Scope: local bullseye: resolved (fixed in 1.2.12.05-1)
debian
CVE-2007-3116MEDIUMCVSS 5.0fixed in maradns 1.2.12.06-1 (bullseye)2007
CVE-2007-3116 [MEDIUM] CVE-2007-3116: maradns - Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote at... Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115. Scope: local bullseye: resolved (fixed in 1.2.12.06-1)
debian
CVE-2007-3115MEDIUMCVSS 5.0fixed in maradns 1.2.12.06-1 (bullseye)2007
CVE-2007-3115 [MEDIUM] CVE-2007-3115: maradns - Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x... Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (memory consumption) via (1) reverse lookups or (2) requests for records in a class other than Internet (IN), a different set of affected versions than CVE-2007-3114 and CVE-2007-3116. Scope: local bullseye: resolved (fi
debian
CVE-2002-2097LOWCVSS 5.0fixed in maradns 0.9.01 (bullseye)2002
CVE-2002-2097 [MEDIUM] CVE-2002-2097: maradns - The compression code in MaraDNS before 0.9.01 allows remote attackers to cause a... The compression code in MaraDNS before 0.9.01 allows remote attackers to cause a denial of service via crafted DNS packets. Scope: local bullseye: resolved (fixed in 0.9.01)
debian