REDHAT-BUG-804770: Medium severity MaraDNS MaraDNS vulnerability
It was reported [1],[2] that MaraDNS suffers from a flaw where it is susceptible to spoofing attacks. Due to an error in the cache update policy, which does not properly handle revoked domain names, a remote attacker could keep a domain name resolvable after it has been deleted from the registration.
This flaw is fixed in versions 1.3.0.7.15 and 1.4.12, and is reported to affect all prior versions.
[1] http://www.maradns.org/changelog.html [2] https://secunia.com/advisories/48492/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-804770?
The severity of REDHAT-BUG-804770 is considered high due to the potential for spoofing attacks.
How do I fix REDHAT-BUG-804770?
To fix REDHAT-BUG-804770, update MaraDNS to the latest version that addresses the vulnerability.
What type of attack is associated with REDHAT-BUG-804770?
REDHAT-BUG-804770 is associated with spoofing attacks due to improper handling of revoked domain names.
Which versions of MaraDNS are affected by REDHAT-BUG-804770?
MaraDNS versions up to 1.3.0.7.15 and 1.4.12 are affected by REDHAT-BUG-804770.
What impact does REDHAT-BUG-804770 have on users?
The impact of REDHAT-BUG-804770 allows remote attackers to keep revoked domain names resolvable, potentially leading to security breaches.