5
CVSSv2

CVE-2008-0061

Published: 03/01/2008 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

MaraDNS 1.0 prior to 1.0.41, 1.2 prior to 1.2.12.08, and 1.3 prior to 1.3.07.04 allows remote malicious users to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records."

Vulnerable Product Search on Vulmon Subscribe to Product

maradns maradns 1.0.00

maradns maradns 1.0.07

maradns maradns 1.0.08

maradns maradns 1.0.09

maradns maradns 1.0.16

maradns maradns 1.0.17

maradns maradns 1.0.24

maradns maradns 1.0.25

maradns maradns 1.0.33

maradns maradns 1.0.34

maradns maradns 1.2.12.02

maradns maradns 1.2.12.03

maradns maradns 1.3.03

maradns maradns 1.3.04

maradns maradns 1.0.01

maradns maradns 1.0.02

maradns maradns 1.0.10

maradns maradns 1.0.11

maradns maradns 1.0.18

maradns maradns 1.0.19

maradns maradns 1.0.26

maradns maradns 1.0.27

maradns maradns 1.0.35

maradns maradns 1.0.36

maradns maradns 1.2.12.04

maradns maradns 1.2.12.05

maradns maradns 1.3.05

maradns maradns 1.3.06

maradns maradns 1.0.05

maradns maradns 1.0.06

maradns maradns 1.0.14

maradns maradns 1.0.15

maradns maradns 1.0.22

maradns maradns 1.0.23

maradns maradns 1.0.30

maradns maradns 1.0.31

maradns maradns 1.0.32

maradns maradns 1.0.39

maradns maradns 1.2.12.01

maradns maradns 1.3.01

maradns maradns 1.3.02

maradns maradns 1.3.07.03

maradns maradns 1.0.03

maradns maradns 1.0.04

maradns maradns 1.0.12

maradns maradns 1.0.13

maradns maradns 1.0.20

maradns maradns 1.0.21

maradns maradns 1.0.28

maradns maradns 1.0.29

maradns maradns 1.0.37

maradns maradns 1.0.38

maradns maradns 1.2.12.06

maradns maradns 1.2.12.07

maradns maradns 1.3.07

maradns maradns 1.3.07.01

maradns maradns 1.3.07.02

Vendor Advisories

Michael Krieger and Sam Trenholme discovered a programming error in MaraDNS, a simple security-aware Domain Name Service server, which might lead to denial of service through malformed DNS packets For the old stable distribution (sarge), this problem has been fixed in version 1027-2 For the stable distribution (etch), this problem has been ...