It was reported [1],[2] that MaraDNS suffers from a flaw where it is susceptible to spoofing attacks. Due to an error in the cache update policy, which does not properly handle revoked domain names, a remote attacker could keep a domain name resolvable after it has been deleted from the registration.
This flaw is fixed in versions 1.3.0.7.15 and 1.4.12, and is reported to affect all prior versions.
[1] http://www.maradns.org/changelog.html [2] https://secunia.com/advisories/48492/