Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2444 to the following vulnerability: parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2444 [2] http://www.openwall.com/lists/oss-security/2010/06/09/4 [3] http://www.openwall.com/lists/oss-security/2010/06/24/5 [4] http://maradns.org/download/maradns-1.4.02-parse_segfault.patch
This issue is resolved in Fedora, however EPEL5 is still vulnerable. The tracking bug for EPEL5 will remain open, but this bug can be closed.