parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a . (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Maradns | Maradns | 1.3.03 (including) | 1.3.03 (including) |
Maradns | Maradns | 1.3.04 (including) | 1.3.04 (including) |
Maradns | Maradns | 1.3.05 (including) | 1.3.05 (including) |
Maradns | Maradns | 1.3.06 (including) | 1.3.06 (including) |
Maradns | Maradns | 1.3.07.01 (including) | 1.3.07.01 (including) |
Maradns | Maradns | 1.3.07.02 (including) | 1.3.07.02 (including) |
Maradns | Maradns | 1.3.07.03 (including) | 1.3.07.03 (including) |
Maradns | Maradns | 1.3.07.04 (including) | 1.3.07.04 (including) |
Maradns | Maradns | 1.3.07.05 (including) | 1.3.07.05 (including) |
Maradns | Maradns | 1.3.07.06 (including) | 1.3.07.06 (including) |
Maradns | Maradns | 1.3.07.07 (including) | 1.3.07.07 (including) |
Maradns | Maradns | 1.3.07.08 (including) | 1.3.07.08 (including) |
Maradns | Maradns | 1.3.07.09 (including) | 1.3.07.09 (including) |
Maradns | Maradns | 1.3.08 (including) | 1.3.08 (including) |
Maradns | Maradns | 1.3.09 (including) | 1.3.09 (including) |
Maradns | Maradns | 1.3.10 (including) | 1.3.10 (including) |
Maradns | Maradns | 1.3.11 (including) | 1.3.11 (including) |
Maradns | Maradns | 1.3.12 (including) | 1.3.12 (including) |
Maradns | Maradns | 1.3.13 (including) | 1.3.13 (including) |
Maradns | Maradns | 1.3.14 (including) | 1.3.14 (including) |
Maradns | Maradns | 1.4.01 (including) | 1.4.01 (including) |
Maradns | Maradns | 1.4.02 (including) | 1.4.02 (including) |
Maradns | Ubuntu | dapper | * |
Maradns | Ubuntu | hardy | * |
Maradns | Ubuntu | jaunty | * |
Maradns | Ubuntu | karmic | * |
Maradns | Ubuntu | lucid | * |
Maradns | Ubuntu | maverick | * |
Maradns | Ubuntu | upstream | * |