Vulnerabilities > CVE-2012-1570 - Unspecified vulnerability in Maradns
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN maradns
nessus
Summary
The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
Vulnerable Configurations
Nessus
NASL family | DNS |
NASL id | MARADNS_2_0_06.NASL |
description | According to its self-reported version number, the MaraDNS server running on the remote host is affected by an issue when updating DNS records in the server |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 73483 |
published | 2014-04-11 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/73483 |
title | MaraDNS < 1.3.07.15 / 1.4.x < 1.4.12 / 2.0.x < 2.0.06 Persistent Ghost Domain Caching |
code |
|
References
- http://osvdb.org/80192
- http://osvdb.org/80192
- http://secunia.com/advisories/48492
- http://secunia.com/advisories/48492
- http://www.maradns.org/changelog.html
- http://www.maradns.org/changelog.html
- http://www.openwall.com/lists/oss-security/2012/03/20/1
- http://www.openwall.com/lists/oss-security/2012/03/20/1
- http://www.openwall.com/lists/oss-security/2012/03/20/10
- http://www.openwall.com/lists/oss-security/2012/03/20/10
- http://www.securitytracker.com/id?1026821
- http://www.securitytracker.com/id?1026821
- https://bugzilla.redhat.com/show_bug.cgi?id=804770
- https://bugzilla.redhat.com/show_bug.cgi?id=804770
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74119
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74119