Описание
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Ссылки
- Vendor Advisory
- Broken LinkVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.9.0 (включая) до 4.9.14 (исключая)Версия от 5.0.0 (включая) до 5.0.4 (исключая)Версия от 1.9.0 (включая) до 1.9.13 (исключая)Версия от 2.0.0 (включая) до 2.0.4 (исключая)Версия от 5.2.0 (включая) до 5.2.9 (исключая)Версия от 5.3.0 (включая) до 5.3.6 (исключая)
Одно из
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00524
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 5.3
ubuntu
4 месяца назад
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVSS3: 5.3
debian
4 месяца назад
An attacker can send a web request that causes unlimited memory alloca ...
CVSS3: 5.3
github
4 месяца назад
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
EPSS
Процентиль: 42%
0.00524
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-770