An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending a DNS query for that record. The issue is due to an integer overflow when checking if the content of the record matches the expected size, allowing an attacker to cause a read past the buffer boundary.
2018-11-01T13:29:00.253
2024-11-21T02:47:52.380
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | powerdns | authoritative | ≤ 3.4.10 | Yes |
Application | powerdns | authoritative | ≤ 4.0.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |