CVE-2022-30256

An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
maradnsmaradns
𝑥
< 3.4.03
maradnsmaradns
3.5.0 ≤
𝑥
< 3.5.0022
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
maradns
bullseye (security)
2.0.13-1.4+deb11u1
fixed
bullseye
2.0.13-1.4+deb11u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
maradns
lunar
Fixed 2.0.13-1.4+deb11u1build0.23.04.1
released
kinetic
ignored
jammy
Fixed 2.0.13-1.4+deb11u1build0.22.04.1
released
focal
Fixed 2.0.13-1.4+deb11u1build0.20.04.1
released
bionic
Fixed 2.0.13-1.2ubuntu0.1~esm1
released
xenial
Fixed 2.0.13-1ubuntu0.1~esm1
released
trusty
ignored