NA

CVE-2022-30256

Published: 19/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in MaraDNS Deadwood up to and including 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

maradns maradns

Vendor Advisories

Debian Bug report logs - #1033252 maradns: CVE-2022-30256 Package: src:maradns; Maintainer for src:maradns is Dariusz Dwornikowski <dariuszdwornikowski@csputpoznanpl>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 20 Mar 2023 19:09:05 UTC Severity: important Tags: security, upstream Reply or s ...
Two vulnerbilities were found in maradns, an open source domain name system (DNS) implementation, that may lead to denial of service and unintended domain name resolution For the oldstable distribution (bullseye), these problems have been fixed in version 2013-14+deb11u1 We recommend that you upgrade your maradns packages For the detailed sec ...