First published: Sat Dec 31 2005(Updated: )
The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ETL Delegate | <=8.10.2 | |
ETL Delegate | =5.9.3 | |
ETL Delegate | =7.7.0 | |
ETL Delegate | =7.7.1 | |
ETL Delegate | =7.8.0 | |
ETL Delegate | =7.8.1 | |
ETL Delegate | =7.8.2 | |
ETL Delegate | =7.9.11 | |
ETL Delegate | =8.3.3 | |
ETL Delegate | =8.3.4 | |
ETL Delegate | =8.4.0 | |
ETL Delegate | =8.5.0 | |
ETL Delegate | =8.9 | |
ETL Delegate | =8.9.1 | |
ETL Delegate | =8.9.2 | |
ETL Delegate | =8.9.3 | |
ETL Delegate | =8.9.4 | |
ETL Delegate | =8.9.5 | |
ETL Delegate | =8.9.6 | |
ETL Delegate | =8.10 | |
ETL Delegate | =8.10.1 | |
ETL Delegate | =5.9 | |
ETL Delegate | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0036 has been classified as a Denial of Service vulnerability that can lead to an infinite loop in affected software.
To fix CVE-2005-0036, upgrade to DeleGate version 8.10.3 or later, or apply any available patches from the vendor.
CVE-2005-0036 affects DeleGate versions up to and including 8.10.2 and several specific earlier versions.
The impact of CVE-2005-0036 is denial of service, potentially making the affected DNS service unresponsive to requests.
CVE-2005-0036 can be exploited remotely by sending specifically crafted DNS packets, thus posing a significant risk.