
CVE-2023-31137 – MaraDNS Integer Underflow Vulnerability in DNS Packet Decompression
https://notcve.org/view.php?id=CVE-2023-31137
09 May 2023 — MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination. The vulnerability exists in the `decomp_get_rddata` function within the `Decompress.c` file. When handling a DNS packet with an Answer RR of qtype 16 (TXT record) and any qclass, if the `rdlength` is smaller than... • https://github.com/samboy/MaraDNS/blob/08b21ea20d80cedcb74aa8f14979ec7c61846663/dns/Decompress.c#L886 • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVE-2022-30256 – Debian Security Advisory 5441-1
https://notcve.org/view.php?id=CVE-2022-30256
18 Nov 2022 — An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names. Se descubrió un problema en MaraDNS Dead... • https://lists.debian.org/debian-lts-announce/2023/06/msg00019.html • CWE-672: Operation on a Resource after Expiration or Release •

CVE-2014-2032
https://notcve.org/view.php?id=CVE-2014-2032
20 Mar 2018 — Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation. Deadwood, en versiones anteriores a la 2.3.09, versiones 3.x anteriores a la 3.2.05; y tal y como se emplea en MaraDNS, en versiones anteriores a la 1.4.14 y en versiones 2.x anteriores a la 2.0.09, permite que atacan... • http://samiam.org/blog/2014-02-12.html • CWE-20: Improper Input Validation CWE-125: Out-of-bounds Read •

CVE-2014-2031
https://notcve.org/view.php?id=CVE-2014-2031
20 Mar 2018 — Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error. Deadwood, en versiones anteriores a la 2.3.09, versiones 3.x anteriores a la 3.2.05; y tal y como se emplea en MaraDNS, en versiones anteriores a la 1.4.14 y en versiones 2.x anteriores a la 2.0.09, permite que atacantes remotos... • http://samiam.org/blog/2014-02-12.html • CWE-125: Out-of-bounds Read •

CVE-2012-1570
https://notcve.org/view.php?id=CVE-2012-1570
28 Mar 2012 — The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. La resolución en MaraDNS antes de v1.3.0.7.15 y v1.4.x antes de v1.4.12 sobrescribe los nombres de caché del servidor y los valores TTL en los registros NS durante la tramitación de una respuesta a una co... • http://osvdb.org/80192 •

CVE-2011-5055
https://notcve.org/view.php?id=CVE-2011-5055
08 Jan 2012 — MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. NOTE: this issue exists because of an incomplete fix for CVE-2012-0024. MaraDNS v1.3.07.12 y v1.4.08 calcula los valores hash de los datos DNS sin restringir la capacidad de desencadenar colisiones hash de forma predec... • http://openwall.com/lists/oss-security/2012/01/03/13 • CWE-20: Improper Input Validation •

CVE-2011-5056
https://notcve.org/view.php?id=CVE-2011-5056
08 Jan 2012 — The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted records in zone files, a different vulnerability than CVE-2012-0024. El servidor autoritativo en maraDNS hasta la versión v2.0.04 calcula los valores hash de los datos del DNS sin restringir la capacidad de obtener colisiones de hash de una forma predecible. Esto po... • http://samiam.org/blog/20111229.html • CWE-400: Uncontrolled Resource Consumption •

CVE-2012-0024 – Gentoo Linux Security Advisory 201202-03
https://notcve.org/view.php?id=CVE-2012-0024
08 Jan 2012 — MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. MaraDNS antes de v1.3.07.12 y v1.4.x antes de v1.4.08 calcula los valores hash de los datos del DNS sin restringir la capacidad de obtener colisiones hash de una forma predecible. Esto permite a atacantes re... • http://openwall.com/lists/oss-security/2012/01/03/13 • CWE-400: Uncontrolled Resource Consumption •

CVE-2011-0520 – Debian Security Advisory 2196-1
https://notcve.org/view.php?id=CVE-2011-0520
28 Jan 2011 — The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow. La función compress_add_dlabel_points en dns/Compress.c de MaraDNS v1.4.03, v1.4.05 y puede que otras versiones, permite a atacantes remotos provocar una denegación de servicio (fallo de se... • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610834 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-2444
https://notcve.org/view.php?id=CVE-2010-2444
25 Jun 2010 — parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file. parse/Csv2_parse.c en MaraDNS V1.3.03, y otras versiones anteriores v1.4.03 no maneja adecuadamente los hombres host que no terminan en el caracter "." (punto), lo que permite a atacantes remotos causar una denegación de servicio (desreferencia de... • http://maradns.org/download/maradns-1.4.02-parse_segfault.patch •