VDB
CVE-2014-2032
CVE-2014-2032
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation.
EPSS 1.64% · 82.3th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.64%
82.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| maradns_project | maradns | 0, 2.0.05 |
| deadwood_project | deadwood | 0, 3.0.01 |
Timeline
- Mar 20, 2018 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 14, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 65595 vdb
- [oss-security] 20140219 Re: CVE request: MaraDNS DoS due to incorrect bounds checking on certain strings mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=1066609 url
- 1029771 vdb
- http://samiam.org/blog/2014-02-12.html url
- maradns-cve20142032-dos(91204) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2014-2032 advisory