An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pdns-recursor | Dec 21, 2018 | Dec 3, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 3, 2018 |
| Debian | — | Upgrade pdns-recursor | Jul 30, 2024 | Dec 3, 2018 |
| Freebsd | — | Upgrade powerdns-recursor | Dec 10, 2018 | Dec 9, 2018 |
| Suse | — | Upgrade pdns-recursor | Dec 18, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade pdns-recursor | Nov 19, 2024 | Dec 3, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub