Release date:
Updated on:
Affected Systems:
MaraDNS 1.x
Unaffected system:
MaraDNS 1.4.9
MaraDNS 1.3.07.13
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51225
Cve id: CVE-2012-0024
MaraDNS is a secure DNS server. It was originally designed to work in Linux and Unix operating systems and has been transplanted to the Windows platform.
MaraDNS has an error in the implementation of hash generation functions, which can be exploited by remote attackers to cause high CPU consumption, application crash, and denial of service to legitimate users.
<* Source: vendor
Link: http://www.maradns.org/changelog.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MaraDNS
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://sourceforge.net/projects/maradns/