Vulnerability Description
Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Technitium | Dns Server | < 10.0 |
Related Weaknesses (CWE)
References
- https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#versionRelease NotesThird Party Advisory
- https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#versionRelease NotesThird Party Advisory
FAQ
What is CVE-2022-48256?
CVE-2022-48256 is a vulnerability with a CVSS score of 7.5 (HIGH). Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.
How severe is CVE-2022-48256?
CVE-2022-48256 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48256?
Check the references section above for vendor advisories and patch information. Affected products include: Technitium Dns Server.