Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8418

Опубликовано: 04 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

Отчет

This vulnerability is classified as moderate severity because it affects the availability of the service rather than compromising data confidentiality or integrity. The CVSS score reflects its impact on system availability, as the DoS attack can lead to significant downtime and service disruption but does not involve unauthorized data access or code execution.

Меры по смягчению последствий

It is advised to upgrade aardvark-dns to version 1.12.1 or higher.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10aardvark-dnsNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/aardvark-dnsNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/containers-commonNot affected
Red Hat Enterprise Linux 9containers-commonNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 9aardvark-dnsFixedRHSA-2025:709413.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2309683containers/aardvark-dns: TCP Query Handling Flaw in Aardvark-dns Leading to Denial of Service

EPSS

Процентиль: 64%
0.00483
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

CVSS3: 7.5
nvd
11 месяцев назад

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

CVSS3: 7.5
debian
11 месяцев назад

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of S ...

CVSS3: 7.5
github
11 месяцев назад

Missing connection timeout in Aardvark-dns

oracle-oval
3 месяца назад

ELSA-2025-7094: aardvark-dns security update (MODERATE)

EPSS

Процентиль: 64%
0.00483
Низкий

7.5 High

CVSS3