CVE-2014-2031: Deadwood Project Deadwood

Medium severity, CVSS 5.9. EPSS: 1.7% chance of exploitation in the next 30 days.

Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error.

Affected products

  • Deadwood Project Deadwood: before 2.3.09 (fixed in 2.3.09); from 3.0.01, before 3.2.05 (fixed in 3.2.05)
  • Maradns Project Maradns: before 1.4.14 (fixed in 1.4.14); from 2.0.05, before 2.0.09 (fixed in 2.0.09)

Published 2018-03-20. Last modified 2026-06-17.