First published: Mon Mar 19 2012(Updated: )
It was reported [1],[2] that MaraDNS suffers from a flaw where it is susceptible to spoofing attacks. Due to an error in the cache update policy, which does not properly handle revoked domain names, a remote attacker could keep a domain name resolvable after it has been deleted from the registration. This flaw is fixed in versions 1.3.0.7.15 and 1.4.12, and is reported to affect all prior versions. [1] <a href="http://www.maradns.org/changelog.html">http://www.maradns.org/changelog.html</a> [2] <a href="https://secunia.com/advisories/48492/">https://secunia.com/advisories/48492/</a>
Affected Software | Affected Version | How to fix |
---|---|---|
MaraDNS | <1.3.0.7.15<1.4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-804770 is considered high due to the potential for spoofing attacks.
To fix REDHAT-BUG-804770, update MaraDNS to the latest version that addresses the vulnerability.
REDHAT-BUG-804770 is associated with spoofing attacks due to improper handling of revoked domain names.
MaraDNS versions up to 1.3.0.7.15 and 1.4.12 are affected by REDHAT-BUG-804770.
The impact of REDHAT-BUG-804770 allows remote attackers to keep revoked domain names resolvable, potentially leading to security breaches.