An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Technitium
Technitium dns Server |
|
Weaknesses | CWE-400 | |
CPEs | cpe:2.3:a:technitium:dns_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Technitium
Technitium dns Server |
|
Metrics |
cvssV3_1
|
Wed, 18 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-18T00:00:00
Updated: 2024-09-18T18:29:11.073Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-28451
Vulnrichment
Updated: 2024-09-18T18:29:03.371Z
NVD
Status : Awaiting Analysis
Published: 2024-09-18T15:15:13.900
Modified: 2024-09-20T12:30:17.483
Link: CVE-2023-28451
Redhat
No data.