cbcvebase.
CVE-2006-4251
published 2006-11-14

CVE-2006-4251: Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 2.9.20-4 (bookworm)pdns 2.9.20-4 (bookworm)
debianpdns-recursor< pdns 2.9.20-4 (bookworm)pdns 2.9.20-4 (bookworm)
open-xchangepdns>= 0 < 2.9.20-42.9.20-4
open-xchangepdns>= 0 < 2.9.20-42.9.20-4
open-xchangepdns>= 0 < 2.9.20-42.9.20-4
open-xchangepdns>= 0 < 2.9.20-42.9.20-4
powerdnsrecursor<= 3.1.3
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor
powerdnsrecursor

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH