Логотип exploitDog
bind:"BDU:2025-11255" OR bind:"CVE-2025-30193"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-11255" OR bind:"CVE-2025-30193"

Количество 9

Количество 9

fstec логотип

BDU:2025-11255

8 месяцев назад

Уязвимость функции setMaxTCPQueriesPerConnection() программного обеспечения PowerDNS DNSdist, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250904-05

5 месяцев назад

Уязвимость dnsdist

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-30193

8 месяцев назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-30193

8 месяцев назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-30193

8 месяцев назад

In some circumstances, when DNSdist is configured to allow an unlimite ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01792-1

8 месяцев назад

Security update for dnsdist

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01745-1

8 месяцев назад

Security update for dnsdist

EPSS: Низкий
github логотип

GHSA-4q3h-v92p-gchj

8 месяцев назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01743-1

8 месяцев назад

Security update for dnsdist

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-11255

Уязвимость функции setMaxTCPQueriesPerConnection() программного обеспечения PowerDNS DNSdist, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
8 месяцев назад
redos логотип
ROS-20250904-05

Уязвимость dnsdist

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimite ...

CVSS3: 7.5
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01792-1

Security update for dnsdist

0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01745-1

Security update for dnsdist

0%
Низкий
8 месяцев назад
github логотип
GHSA-4q3h-v92p-gchj

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01743-1

Security update for dnsdist

8 месяцев назад

Уязвимостей на страницу