MaraDNS 1.3.03 to 1.3.07.10 / 1.4.x < 1.4.03 NULL Pointer Dereference Local DoS (Linux)

medium Nessus Plugin ID 73479

Synopsis

The DNS server running on the remote host is affected by a denial of service vulnerability.

Description

According to its self-reported version number, the MaraDNS server running on the remote host is affected by a NULL pointer dereference issue due to improper handling of hostnames not ending with a dot character in 'csv2' zone files. This issue could allow a remote attacker to crash the DNS server, resulting in a denial of service.

Solution

Upgrade to MaraDNS version 1.3.07.10 / 1.4.03 or later or apply the relevant patch.

See Also

http://www.nessus.org/u?dd837053

http://maradns.samiam.org/security.html

Plugin Details

Severity: Medium

ID: 73479

File Name: maradns_1_4_03.nasl

Version: 1.5

Type: remote

Family: DNS

Published: 4/11/2014

Updated: 11/26/2019

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2010-2444

Vulnerability Information

CPE: cpe:/a:maradns:maradns

Required KB Items: Settings/ParanoidReport, maradns/version, maradns/num_ver

Exploit Ease: No known exploits are available

Patch Publication Date: 2/2/2010

Vulnerability Publication Date: 2/2/2010

Reference Information

CVE: CVE-2010-2444

BID: 40745