Several security issues were fixed in MaraDNS.. ========================================================================== Ubuntu Security Notice USN-6271-1 August 03, 2023 maradns vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in MaraDNS. Software Description: - maradns: A small open-source DNS server Details: Xiang Li discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2022-30256) Huascar Tejeda discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-31137) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: duende 2.0.13-1.4+deb11u1build0.23.04.1 maradns 2.0.13-1.4+deb11u1build0.23.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.23.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.23.04.1 Ubuntu 22.04 LTS: duende 2.0.13-1.4+deb11u1build0.22.04.1 maradns 2.0.13-1.4+deb11u1build0.22.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.22.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.22.04.1 Ubuntu 20.04 LTS: duende 2.0.13-1.4+deb11u1build0.20.04.1 maradns 2.0.13-1.4+deb11u1build0.20.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.20.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): duende 2.0.13-1.2ubuntu0.1~esm1 maradns 2.0.13-1.2ubuntu0.1~esm1 maradns-deadwood 2.0.13-1.2ubuntu0.1~esm1 maradns-zoneserver 2.0.13-1.2ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): duende 2.0.13-1ubuntu0.1~esm1 maradns 2.0.13-1ubuntu0.1~esm1 maradns-deadwood 2.0.13-1ubuntu0.1~esm1 maradns-zoneserver 2.0.13-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6271-1 CVE-2022-30256, CVE-2023-31137 Package Information: https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.23.04.1 https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.22.04.1 https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.20.04.1 . A number of vulnerabilities addressed in MaraDNS for Ubuntu, impacting various releases. Update suggestions issued.. MaraDNS Security Update, Ubuntu Security Notice, DNS Server Issues. . Severity: Important. LinuxSecurity.com Team
Brief introduction Two vulnerbilities were found in maradns, an open source domain name system (DNS) implementation, that may lead to denial of service and . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5441-1
Security fix for CVE-2023-31137, CVE-2022-30256. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0c012f6245 2023-05-25 01:10:39.287243 --------------------------------------------------------------------------------Name : maradns Product : Fedora 38 Version : 3.5.0036 Release : 1.fc38 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-31137, CVE-2022-30256 --------------------------------------------------------------------------------ChangeLog: * Tue May 16 2023 Tomasz Torcz - 3.5.0036-1 - new version 3.5.0036 (rhbz#2149110, rhbz#2180267) - fixes CVE-2023-31137 (rhbz#2207551) --------------------------------------------------------------------------------References: [ 1 ] Bug #2207550 - CVE-2023-31137 maradns: integer underflow in DNS packet decompression https://bugzilla.redhat.com/show_bug.cgi?id=2207550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0c012f6245' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Security fix for CVE-2023-31137, CVE-2022-30256. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-cdce244fb8 2023-05-25 00:59:24.928504 --------------------------------------------------------------------------------Name : maradns Product : Fedora 37 Version : 3.5.0036 Release : 1.fc37 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-31137, CVE-2022-30256 --------------------------------------------------------------------------------ChangeLog: * Tue May 16 2023 Tomasz Torcz - 3.5.0036-1 - new version 3.5.0036 (rhbz#2149110, rhbz#2180267) - fixes CVE-2023-31137 (rhbz#2207551) --------------------------------------------------------------------------------References: [ 1 ] Bug #2207550 - CVE-2023-31137 maradns: integer underflow in DNS packet decompression https://bugzilla.redhat.com/show_bug.cgi?id=2207550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cdce244fb8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
This update fixes Denial-of-Service vulnerability in â€zoneserver†component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14033 2015-08-27 19:40:20.010620 -------------------------------------------------------------------------------- Name : maradns Product : Fedora 21 Version : 2.0.12 Release : 1.fc21 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. -------------------------------------------------------------------------------- Update Information: This update fixes Denial-of-Service vulnerability in â€zoneserver†component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update maradns' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- . Announcement Alert FEDORA-2015-14034 addresses a critical Denial-of-Service vulnerability in the maradns zoneserver module.. MaradnsUpdate, Fedora Security, Denial-of-Service Fix. . Severity: Critical. LinuxSecurity.com Team
This update fixes Denial-of-Service vulnerability in â€zoneserver†component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14032 2015-08-27 17:52:04.306247 -------------------------------------------------------------------------------- Name : maradns Product : Fedora 22 Version : 2.0.12 Release : 1.fc22 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. -------------------------------------------------------------------------------- Update Information: This update fixes Denial-of-Service vulnerability in â€zoneserver†component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update maradns' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . This patch resolves a service interruption vulnerability found in the zoneserver module of Fedora 22'sMaraDNS software.. Fedora Update, Denial of Service, MaraDNS Security, Software Patch. . Severity: Critical. LinuxSecurity.com Team
Witold Baryluk discovered that MaraDNS, a simple security-focused Domain Name Service server, may overflow an internal buffer when handling requests with a large number of labels, causing a server crash and the consequent denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2196-1
Michael Krieger and Sam Trenholme discovered a programming error in MaraDNS, a simple security-aware Domain Name Service server, which might to denial of service through malformed DNS packets.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1445-1
Get the latest Linux and open source security news straight to your inbox.