CVE-2005-2302Powerdns vulnerability

5 documents5 sources
Severity
2.1LOWNVD
EPSS
0.0%
top 99.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 19
Latest updateMay 1

Description

PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDpowerdns/powerdns17 versions+16
Debianopen-xchange/pdns< 2.9.18-1+3

🔴Vulnerability Details

3
GHSA
GHSA-6w24-r92j-wj7q: PowerDNS before 22022-05-01
OSV
CVE-2005-2302: PowerDNS before 22005-07-19
CVEList
CVE-2005-2302: PowerDNS before 22005-07-19

📋Vendor Advisories

1
Debian
CVE-2005-2302: pdns - PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addr...2005
CVE-2005-2302 — Powerdns vulnerability | cvebase