First published: Fri Jun 25 2010(Updated: )
parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MaraDNS | =1.3.03 | |
MaraDNS | =1.3.04 | |
MaraDNS | =1.3.05 | |
MaraDNS | =1.3.06 | |
MaraDNS | =1.3.07.01 | |
MaraDNS | =1.3.07.02 | |
MaraDNS | =1.3.07.03 | |
MaraDNS | =1.3.07.04 | |
MaraDNS | =1.3.07.05 | |
MaraDNS | =1.3.07.06 | |
MaraDNS | =1.3.07.07 | |
MaraDNS | =1.3.07.08 | |
MaraDNS | =1.3.07.09 | |
MaraDNS | =1.3.08 | |
MaraDNS | =1.3.09 | |
MaraDNS | =1.3.10 | |
MaraDNS | =1.3.11 | |
MaraDNS | =1.3.12 | |
MaraDNS | =1.3.13 | |
MaraDNS | =1.3.14 | |
MaraDNS | =1.4.01 | |
MaraDNS | =1.4.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2444 has a medium severity rating, leading to a denial of service via a NULL pointer dereference.
To fix CVE-2010-2444, upgrade MaraDNS to version 1.4.03 or later.
CVE-2010-2444 affects MaraDNS versions 1.3.03 to 1.3.14.
CVE-2010-2444 allows remote attackers to execute a denial of service attack by exploiting malformed csv2 zone files.
Yes, a patch for CVE-2010-2444 can be found in the upgrade to MaraDNS version 1.4.03.