CVE-2022-33993
Last modified
CVE-2022-33993 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Domain Name Relay Daemon Project | Domain Name Relay Daemon | 2.20.3 |
References
- http://dnrd.sourceforge.net/Product, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/1Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/jeitnerThird Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
- http://dnrd.sourceforge.net/Product, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/1Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/jeitnerThird Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33993?
How severe is CVE-2022-33993?
How do I fix CVE-2022-33993?
Are you affected by CVE-2022-33993?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
