Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-31137

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-191 Subdesbordamiento de entero
Fecha de publicación:
09/05/2023
Última modificación:
07/03/2024

Descripción

*** Pendiente de traducción *** MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Service by triggering an abnormal program termination.<br /> <br /> The vulnerability exists in the `decomp_get_rddata` function within the `Decompress.c` file. When handling a DNS packet with an Answer RR of qtype 16 (TXT record) and any qclass, if the `rdlength` is smaller than `rdata`, the result of the line `Decompress.c:886` is a negative number `len = rdlength - total;`. This value is then passed to the `decomp_append_bytes` function without proper validation, causing the program to attempt to allocate a massive chunk of memory that is impossible to allocate. Consequently, the program exits with an error code of 64, causing a Denial of Service.<br /> <br /> One proposed fix for this vulnerability is to patch `Decompress.c:887` by breaking `if(len

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:maradns:maradns:*:*:*:*:*:*:*:* 3.4.10 (excluyendo)
cpe:2.3:a:maradns:maradns:*:*:*:*:*:*:*:* 3.5.0001 (incluyendo) 3.5.0036 (excluyendo)
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*