Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-25583

Опубликовано: 25 апр. 2024
Источник: debian

Описание

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pdns-recursorfixed4.9.5-1package
pdns-recursornot-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/04/24/1

  • Introduced by: https://github.com/PowerDNS/pdns/commit/3f427fc636282792374e2eb754621f0520e52402 (rec-4.9.4)

  • Fixed by: https://github.com/PowerDNS/pdns/commit/3d16f2f49c22326e5a72f074c2a1f1b45769cb3f (rec-4.9.5)

  • Introduced by: https://github.com/PowerDNS/pdns/commit/c090cc8b9198a9ee9155486894505a86878e30ee (rec-4.8.7)

  • Fixed by: https://github.com/PowerDNS/pdns/commit/e1247da968077ee7c58fa41447057ee2a2b09fc9 (rec-4.8.8)

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

CVSS3: 7.5
nvd
почти 2 года назад

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

suse-cvrf
почти 2 года назад

Security update for pdns-recursor

CVSS3: 7.5
github
почти 2 года назад

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.