CVE Vulnerabilities

CVE-2012-1570

Published: Mar 28, 2012 | Modified: Aug 14, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Affected Software

Name Vendor Start Version End Version
Maradns Maradns * 1.3.07.15 (excluding)
Maradns Maradns 1.4.0 (including) 1.4.12 (excluding)
Maradns Ubuntu artful *
Maradns Ubuntu hardy *
Maradns Ubuntu lucid *
Maradns Ubuntu maverick *
Maradns Ubuntu natty *
Maradns Ubuntu oneiric *
Maradns Ubuntu precise *
Maradns Ubuntu quantal *
Maradns Ubuntu raring *
Maradns Ubuntu saucy *
Maradns Ubuntu upstream *
Maradns Ubuntu utopic *
Maradns Ubuntu vivid *
Maradns Ubuntu wily *
Maradns Ubuntu yakkety *
Maradns Ubuntu zesty *

References