CVE-2014-2031

NameCVE-2014-2031
DescriptionDeadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
maradns (PTS)buster2.0.13-1.2fixed
buster (security)2.0.13-1.2+deb10u1fixed
bullseye, bullseye (security)2.0.13-1.4+deb11u1fixed
sid2.0.13-1.6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
maradnssource(unstable)(not affected)

Notes

- maradns <not-affected> (Deadwood resolver not enabled)
https://github.com/samboy/MaraDNS/commit/f015495d221f1c2b2f10db38e87cecf3839d6093

Search for package or bug name: Reporting problems