7.5
CVSSv2

CVE-2011-0520

Published: 28/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote malicious users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

maradns maradns 1.4.03

maradns maradns 1.4.05

Vendor Advisories

Debian Bug report logs - #610834 maradns: crash on long name queries Package: maradns; Maintainer for maradns is Dariusz Dwornikowski <dariuszdwornikowski@csputpoznanpl>; Source for maradns is src:maradns (PTS, buildd, popcon) Reported by: "Witold Baryluk" <baryluk@smpifujedupl> Date: Sun, 23 Jan 2011 04:12:0 ...
Witold Baryluk discovered that MaraDNS, a simple security-focused Domain Name System server, may overflow an internal buffer when handling requests with a large number of labels, causing a server crash and the consequent denial of service For the oldstable distribution (lenny), this problem has been fixed in version 130709-21 For the stable d ...