CVE-2012-0024: High severity maradns project maradns vulnerability
MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0024?
CVE-2012-0024 has a severity rating of low to medium due to its potential for denial of service through increased CPU consumption.
How do I fix CVE-2012-0024?
To fix CVE-2012-0024, upgrade MaraDNS to version 1.3.07.12 or 1.4.08 or later.
What kind of attacks can exploit CVE-2012-0024?
CVE-2012-0024 can be exploited by remote attackers sending crafted DNS queries to cause CPU resource exhaustion.
Which versions of MaraDNS are affected by CVE-2012-0024?
MaraDNS versions before 1.3.07.12 and 1.4.x before 1.4.08 are affected by CVE-2012-0024.
What is the impact of CVE-2012-0024?
The impact of CVE-2012-0024 is primarily denial of service, leading to significant CPU load and potential service disruption.