Powerdns

Recursor

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 29.11.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:27

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.

  • EPSS 0.09%
  • Veröffentlicht 29.11.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:08

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

  • EPSS 0.04%
  • Veröffentlicht 09.11.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:29

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone ...

  • EPSS 0%
  • Veröffentlicht 11.09.2018 13:29:01
  • Zuletzt bearbeitet 21.11.2024 02:57:24

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing ch...

  • EPSS 0.01%
  • Veröffentlicht 11.09.2018 13:29:01
  • Zuletzt bearbeitet 21.11.2024 02:57:24

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing ch...

  • EPSS 0.09%
  • Veröffentlicht 11.09.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 02:57:23

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which mi...

  • EPSS 0.33%
  • Veröffentlicht 27.07.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:06

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remot...

  • EPSS 0%
  • Veröffentlicht 23.01.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:03

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign i...

  • EPSS 0%
  • Veröffentlicht 23.01.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:03

A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript co...

  • EPSS 0.01%
  • Veröffentlicht 23.01.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:03

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and remov...