First published: Tue Mar 20 2018(Updated: )
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Maradns Project Maradns | <1.4.14 | |
Maradns Project Maradns | >=2.0.05<2.0.09 | |
Deadwood Project Deadwood | <2.3.09 | |
Deadwood Project Deadwood | >=3.0.01<3.2.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2032 is classified as a denial of service vulnerability that can cause crashes in affected software.
CVE-2014-2032 affects Deadwood versions prior to 2.3.09 and 3.x versions before 3.2.05, as well as MaraDNS versions prior to 1.4.14 and 2.x before 2.0.09.
To fix CVE-2014-2032, update Deadwood to version 2.3.09 or later and MaraDNS to version 1.4.14 or later.
Exploiting CVE-2014-2032 can lead to a denial of service, resulting in out-of-bounds read and the crashing of the service.
Mitigation of CVE-2014-2032 involves restricting access to the affected DNS servers and ensuring that only trusted sources can perform recursive queries.