FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0520

This CVE name corresponds to:

Entered Topic
2011-01-31 maradns -- denial of service when resolving a long DNS hostname

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0520
Phase Assigned(20110120)

Description

The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow.

References

Source Reference
MLIST [oss-security] 20110123 CVE request: MaraDNS DoS via long queries
MLIST [oss-security] 20110124 Re: CVE request: MaraDNS DoS via long queries
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610834
DEBIAN DSA-2196
BID 45966
OSVDB 70630
SECUNIA 43027
SECUNIA 43107
VUPEN ADV-2011-0699
XF maradns-compressadddlabelpoints-bo(64885)