CVE-2004-0789: Medium severity Delegate DeleGate vulnerability

Published Dec 31, 2004
·
Updated

Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.

Affected Software

98 affected components
Delegate DeleGate=7.7.0
Delegate DeleGate=7.7.1
Delegate DeleGate=7.8.0
Delegate DeleGate=7.8.1
Delegate DeleGate=7.8.2
Delegate DeleGate=7.9.11
Delegate DeleGate=8.3.3
Delegate DeleGate=8.3.4
Delegate DeleGate=8.4.0
Delegate DeleGate=8.5.0
Delegate DeleGate=8.9
Delegate DeleGate=8.9.1
Delegate DeleGate=8.9.2
Delegate DeleGate=8.9.3
Delegate DeleGate=8.9.4
Delegate DeleGate=8.9.5
DNRD dnrd=1.0
DNRD dnrd=1.1
DNRD dnrd=1.2
DNRD dnrd=1.3
DNRD dnrd=1.4
DNRD dnrd=2.0
DNRD dnrd=2.1
DNRD dnrd=2.2
DNRD dnrd=2.3
DNRD dnrd=2.4
DNRD dnrd=2.5
DNRD dnrd=2.6
DNRD dnrd=2.7
DNRD dnrd=2.8
DNRD dnrd=2.9
DNRD dnrd=2.10
Don Moore Mydns=0.6
Don Moore Mydns=0.7
Don Moore Mydns=0.8
Don Moore Mydns=0.9
Don Moore Mydns=0.10.0
MaraDNS MaraDNS=0.5.28
MaraDNS MaraDNS=0.5.29
MaraDNS MaraDNS=0.5.30
MaraDNS MaraDNS=0.5.31
MaraDNS MaraDNS=0.8.05
Pliant Pliant Dns Server
Posadis Posadis=0.50.4
Posadis Posadis=0.50.5
Posadis Posadis=0.50.6
Posadis Posadis=0.50.7
Posadis Posadis=0.50.8
Posadis Posadis=0.50.9
Posadis Posadis=0.60.0
Posadis Posadis=0.60.1
Posadis Posadis=m5pre1
Posadis Posadis=m5pre2
Qbik WinGate=3.0
Qbik WinGate=4.0.1
Qbik WinGate=4.1_beta_a
Qbik WinGate=6.0
Qbik WinGate=6.0.1_build_993
Qbik WinGate=6.0.1_build_995
Team Johnlong Raidendnsd
Axis 2100 Network Camera=2.0
Axis 2100 Network Camera=2.01
Axis 2100 Network Camera=2.02
Axis 2100 Network Camera=2.03
Axis 2100 Network Camera=2.12
Axis 2100 Network Camera=2.30
Axis 2100 Network Camera=2.31
Axis 2100 Network Camera=2.32
Axis 2100 Network Camera=2.33
Axis 2100 Network Camera=2.34
Axis 2100 Network Camera=2.40
Axis 2100 Network Camera=2.41
Axis 2110 Network Camera=2.12
Axis 2110 Network Camera=2.30
Axis 2110 Network Camera=2.31
Axis 2110 Network Camera=2.32
Axis 2110 Network Camera=2.34
Axis 2110 Network Camera=2.40
Axis 2110 Network Camera=2.41
Axis 2120 Network Camera=2.12
Axis 2120 Network Camera=2.30
Axis 2120 Network Camera=2.31
Axis 2120 Network Camera=2.32
Axis 2120 Network Camera=2.34
Axis 2120 Network Camera=2.40
Axis 2120 Network Camera=2.41
Axis 2400 Video Server=3.11
Axis 2400 Video Server=3.12
Axis 2401 Video Server=3.12
Axis 2420 Network Camera=2.12
Axis 2420 Network Camera=2.30
Axis 2420 Network Camera=2.31
Axis 2420 Network Camera=2.32
Axis 2420 Network Camera=2.33
Axis 2420 Network Camera=2.34
Axis 2420 Network Camera=2.40
Axis 2420 Network Camera=2.41
Axis 2460 Network Dvr=3.12

Event History

Dec 31, 2004
CVE Published
05:00 AM
Sep 1, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2004-0789?

CVE-2004-0789 is classified as a high severity vulnerability due to its potential to cause denial of service.

2

How do I fix CVE-2004-0789?

To fix CVE-2004-0789, you should update the affected DNS implementations to their latest versions that have patched this vulnerability.

3

What systems are affected by CVE-2004-0789?

CVE-2004-0789 affects multiple DNS implementations, including Poslib, Axis Network products, and Men & Mice Suite, among others.

4

Who can exploit CVE-2004-0789?

Remote attackers can exploit CVE-2004-0789 to disrupt DNS services, resulting in denial of service conditions.

5

What are the symptoms of an exploit of CVE-2004-0789?

Exploitation of CVE-2004-0789 may lead to high CPU usage and significant network bandwidth consumption, making services unavailable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203