Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-4q3h-v92p-gchj

около 1 года назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-30193

около 1 года назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-30193

около 1 года назад

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-30193

около 1 года назад

In some circumstances, when DNSdist is configured to allow an unlimite ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01792-1

около 1 года назад

Security update for dnsdist

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01745-1

около 1 года назад

Security update for dnsdist

EPSS: Низкий
fstec логотип

BDU:2025-11255

около 1 года назад

Уязвимость функции setMaxTCPQueriesPerConnection() программного обеспечения PowerDNS DNSdist, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01743-1

около 1 года назад

Security update for dnsdist

EPSS: Низкий
redos логотип

ROS-20250904-05

11 месяцев назад

Уязвимость dnsdist

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4q3h-v92p-gchj

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.

CVSS3: 7.5
1%
Низкий
около 1 года назад
debian логотип
CVE-2025-30193

In some circumstances, when DNSdist is configured to allow an unlimite ...

CVSS3: 7.5
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01792-1

Security update for dnsdist

1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01745-1

Security update for dnsdist

1%
Низкий
около 1 года назад
fstec логотип
BDU:2025-11255

Уязвимость функции setMaxTCPQueriesPerConnection() программного обеспечения PowerDNS DNSdist, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01743-1

Security update for dnsdist

около 1 года назад
redos логотип
ROS-20250904-05

Уязвимость dnsdist

CVSS3: 7.5
1%
Низкий
11 месяцев назад

Уязвимостей на страницу