VulnerabilityModified
CVE-2022-33993
Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
MEDIUM 5.3EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- domain name relay daemon project/domain name relay daemon
- Source
- cve@mitre.org
References
- http://dnrd.sourceforge.net/Product, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/1Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/jeitnerThird Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
- http://dnrd.sourceforge.net/Product, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/1Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity21/presentation/jeitnerThird Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.