CVE Vulnerabilities

CVE-2012-1570

Published: Mar 28, 2012 | Modified: Aug 14, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Affected Software

Name Vendor Start Version End Version
Maradns Maradns * 1.3.07.15 (excluding)
Maradns Maradns 1.4.0 (including) 1.4.12 (excluding)

References