CVE-2011-5055: Input Validation
Published Jan 8, 2012
·Updated
MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. NOTE: this issue exists because of an incomplete fix for CVE-2012-0024.
Affected Software
2 affected components
MaraDNS MaraDNS=1.4.08
MaraDNS MaraDNS=1.3.07.012
Remediation
Patch Available
Event History
Jan 8, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5055?
CVE-2011-5055 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2011-5055?
To fix CVE-2011-5055, upgrade to MaraDNS version 1.4.09 or later.
3
What is the impact of CVE-2011-5055?
The impact of CVE-2011-5055 is increased CPU consumption leading to potential service disruption.
4
Who is affected by CVE-2011-5055?
CVE-2011-5055 affects users of MaraDNS versions 1.3.07.12 and 1.4.08.
5
Can CVE-2011-5055 be exploited remotely?
Yes, CVE-2011-5055 can be exploited remotely through crafted DNS queries.