CVE-2022-33992
Summary
| CVE | CVE-2022-33992 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-15 12:15:00 UTC |
| Updated | 2022-08-18 17:32:00 UTC |
| Description | DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Domain Name Relay Daemon Project | Domain Name Relay Daemon | 2.20.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DNRD - Domain Name Relay Daemon | MISC | dnrd.sourceforge.net | |
| oss-security - Multiple DNS Cache poisoning vulnerabilities in dnrd DNS forwarder (CVE-2022-33993, CVE-2022-33992) | MISC | www.openwall.com | |
| XDRI Attacks - and - How to Enhance Resilience of Residential Routers | USENIX | MISC | www.usenix.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.