Summary
The remote host is missing an update to maradns
announced via advisory DSA 2196-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202196-1
Insight
Witold Baryluk discovered that MaraDNS, a simple security-focused Domain Name Service server, may overflow an internal buffer when handling requests with a large number of labels, causing a server crash and the consequent denial of service.
For the oldstable distribution (lenny), this problem has been fixed in version 1.3.07.09-2.1.
For the stable distribution (squeeze) and greater this problem had already been fixed in version 1.4.03-1.1.
We recommend that you upgrade your maradns packages.
Severity
Classification
-
CVE CVE-2011-0520 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities