2024-12-08 03:06:42 +00:00

143 lines
4.9 KiB
JSON

{
"id": "CVE-2022-30256",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-11-19T00:15:10.497",
"lastModified": "2024-11-21T07:02:27.020",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for \"Ghost\" domain names."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en MaraDNS Deadwood hasta 3.5.0021 que permite la variante V1 de resoluci\u00f3n de nombres de dominio no deseada. Un nombre de dominio revocado a\u00fan se puede resolver durante mucho tiempo, incluidos dominios caducados y dominios maliciosos eliminados. Los efectos de un exploit ser\u00edan generalizados y de gran impacto, porque la explotaci\u00f3n se ajusta a las especificaciones y pr\u00e1cticas operativas de DNS de facto, y supera los parches de mitigaci\u00f3n actuales para los nombres de dominio \"Ghost\""
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-672"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:maradns:maradns:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.4.03",
"matchCriteriaId": "043E0914-15F6-4D95-AA7D-367C131CCE2B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:maradns:maradns:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.5.0",
"versionEndExcluding": "3.5.0022",
"matchCriteriaId": "F46DBDE0-82CE-484D-8E75-0D6D61FEF83F"
}
]
}
]
}
],
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00019.html",
"source": "cve@mitre.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3VSMLJX25MXGQ6A7UPOGK7VPUVDESPHL/",
"source": "cve@mitre.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NB7LDZM5AGWC5BHHQHW6CP5OFNBBKFOQ/",
"source": "cve@mitre.org"
},
{
"url": "https://maradns.samiam.org/",
"source": "cve@mitre.org",
"tags": [
"Product",
"Vendor Advisory"
]
},
{
"url": "https://maradns.samiam.org/security.html#CVE-2022-30256",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.debian.org/security/2023/dsa-5441",
"source": "cve@mitre.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00019.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3VSMLJX25MXGQ6A7UPOGK7VPUVDESPHL/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NB7LDZM5AGWC5BHHQHW6CP5OFNBBKFOQ/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://maradns.samiam.org/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Product",
"Vendor Advisory"
]
},
{
"url": "https://maradns.samiam.org/security.html#CVE-2022-30256",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.debian.org/security/2023/dsa-5441",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}