CVE-2022-30256
Summary
| CVE | CVE-2022-30256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-19 00:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names. |
Risk And Classification
Problem Types: CWE-672
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MaraDNS - a small open-source DNS server | MISC | maradns.samiam.org | |
| [SECURITY] Fedora 37 Update: maradns-3.5.0036-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 3457-1] maradns security update | MLIST | lists.debian.org | |
| MaraDNS - a small open-source DNS server | MISC | maradns.samiam.org | |
| [SECURITY] Fedora 37 Update: maradns-3.5.0036-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-5441-1 maradns | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 38 Update: maradns-3.5.0036-1.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: maradns-3.5.0036-1.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181878 Debian Security Update for maradns (DLA 3457-1)
- 199635 Ubuntu Security Notification for Mara Domain Name System (DNS) Vulnerabilities (USN-6271-1)
- 283996 Fedora Security Update for maradns (FEDORA-2023-cdce244fb8)
- 284134 Fedora Security Update for maradns (FEDORA-2023-0c012f6245)
- 285314 Fedora Security Update for maradns (FEDORA-2023-3dd938a14d)
- 6000241 Debian Security Update for maradns (DSA 5441-1)