An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pdns | Aug 22, 2024 | Oct 2, 2020 |
| Debian | — | Upgrade pdns | Jul 30, 2024 | Oct 2, 2020 |
| Freebsd | — | Upgrade powerdns | Sep 29, 2020 | Sep 24, 2020 |
| Gentoo Linux | — | Upgrade net-dns/pdns. | Dec 29, 2020 | Oct 2, 2020 |
| Suse | — | Upgrade pdns-backend-remoteUpgrade pdns-backend-postgresqlUpgrade pdns-backend-mysqlUpgrade pdnsUpgrade pdns-backend-sqlite3Upgrade pdns-backend-ldapUpgrade pdns-backend-godbcUpgrade pdns-backend-geoipUpgrade pdns-backend-mydnsUpgrade pdns-backend-lua | Sep 29, 2020 | Sep 22, 2020 |
| Ubuntu | — | Upgrade pdns-server (Ubuntu Pro)Upgrade pdns-tools (Ubuntu Pro)Upgrade pdns-recursor (Ubuntu Pro) | Jan 15, 2025 | Oct 2, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub