MaraDNS Denial of Service Vulnerability
BID:3852
Info
MaraDNS Denial of Service Vulnerability
| Bugtraq ID: | 3852 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2002 12:00AM |
| Updated: | Jan 10 2002 12:00AM |
| Credit: | Published in the MaraDNS changelog. |
| Vulnerable: |
MaraDNS MaraDNS 0.9 .00 MaraDNS MaraDNS 0.8.99 MaraDNS MaraDNS 0.5.30 MaraDNS MaraDNS 0.5.29 MaraDNS MaraDNS 0.5.28 |
| Not Vulnerable: |
MaraDNS MaraDNS 0.9 .01 MaraDNS MaraDNS 0.5.31 |
Discussion
MaraDNS Denial of Service Vulnerability
MaraDNS is secure, authoritative DNS server. It was originally written for Linux and Unix based systems, and has been ported to Microsoft Windows. MaraDNS has been designed to be secure, and includes features such as a buffer overflow resistant string library and the requirement to run as a non privileged user in a chroot environment.
A denial of service vulnerability exists in some versions of MaraDNS. It is possible to affect availability of the server, through exploitation of an error in the compression handling for DNS communications. Further details on this vulnerability are not available at this time.
Earlier versions of MaraDNS share this vulnerability.
MaraDNS is secure, authoritative DNS server. It was originally written for Linux and Unix based systems, and has been ported to Microsoft Windows. MaraDNS has been designed to be secure, and includes features such as a buffer overflow resistant string library and the requirement to run as a non privileged user in a chroot environment.
A denial of service vulnerability exists in some versions of MaraDNS. It is possible to affect availability of the server, through exploitation of an error in the compression handling for DNS communications. Further details on this vulnerability are not available at this time.
Earlier versions of MaraDNS share this vulnerability.
Exploit / POC
MaraDNS Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MaraDNS Denial of Service Vulnerability
Solution:
An updated version has been made available:
MaraDNS MaraDNS 0.5.28
MaraDNS MaraDNS 0.5.29
MaraDNS MaraDNS 0.5.30
MaraDNS MaraDNS 0.8.99
MaraDNS MaraDNS 0.9 .00
Solution:
An updated version has been made available:
MaraDNS MaraDNS 0.5.28
-
MaraDNS maradns-0.5.31.tar.bz2
http://www.maradns.org/download/maradns-0.5.31.tar.bz2
MaraDNS MaraDNS 0.5.29
-
MaraDNS maradns-0.5.31.tar.bz2
http://www.maradns.org/download/maradns-0.5.31.tar.bz2
MaraDNS MaraDNS 0.5.30
-
MaraDNS maradns-0.5.31.tar.bz2
http://www.maradns.org/download/maradns-0.5.31.tar.bz2
MaraDNS MaraDNS 0.8.99
-
MaraDNS maradns-0.9.01.tar.gz
http://www.maradns.org/download/maradns-0.9.01.tar.gz
MaraDNS MaraDNS 0.9 .00
-
MaraDNS maradns-0.9.01.tar.gz
http://www.maradns.org/download/maradns-0.9.01.tar.gz