CVE-2022-33993
Summary
| CVE | CVE-2022-33993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-15 12:15:00 UTC |
| Updated | 2022-08-18 17:48:00 UTC |
| Description | Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Domain Name Relay Daemon Project | Domain Name Relay Daemon | 2.20.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DNRD - Domain Name Relay Daemon | MISC | dnrd.sourceforge.net | |
| Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS | USENIX | MISC | www.usenix.org | |
| oss-security - Multiple DNS Cache poisoning vulnerabilities in dnrd DNS forwarder (CVE-2022-33993, CVE-2022-33992) | MISC | www.openwall.com | |
| XDRI Attacks - and - How to Enhance Resilience of Residential Routers | USENIX | MISC | www.usenix.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.