CVE-2006-4252
published 2006-11-14CVE-2006-4252: PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.91%
92.4th percentile
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns-recursor 3.1.4-1 (bookworm) | pdns-recursor 3.1.4-1 (bookworm) |
| debian | pdns-recursor | < pdns-recursor 3.1.4-1 (bookworm) | pdns-recursor 3.1.4-1 (bookworm) |
| powerdns | recursor | <= 3.1.3 | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
| powerdns | recursor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-4252: pdns - PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of...
vendor_debian·2006·CVSS 5.0
CVE-2006-4252 [MEDIUM] CVE-2006-4252: pdns - PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of...
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-mx38-c6fm-chc9: PowerDNS Recursor 3
ghsa_unreviewed·2022-05-01
CVE-2006-4252 [MEDIUM] GHSA-mx38-c6fm-chc9: PowerDNS Recursor 3
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
OSV
CVE-2006-4252: PowerDNS Recursor 3
osv·2006-11-14·CVSS 5.0
CVE-2006-4252 [MEDIUM] CVE-2006-4252: PowerDNS Recursor 3
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://doc.powerdns.com/powerdns-advisory-2006-02.htmlhttp://lists.suse.com/archive/suse-security-announce/2006-Nov/0007.htmlhttp://secunia.com/advisories/22824http://secunia.com/advisories/22976http://www.securityfocus.com/bid/21037http://www.vupen.com/english/advisories/2006/4484https://exchange.xforce.ibmcloud.com/vulnerabilities/30257http://doc.powerdns.com/powerdns-advisory-2006-02.htmlhttp://lists.suse.com/archive/suse-security-announce/2006-Nov/0007.htmlhttp://secunia.com/advisories/22824http://secunia.com/advisories/22976http://www.securityfocus.com/bid/21037http://www.vupen.com/english/advisories/2006/4484https://exchange.xforce.ibmcloud.com/vulnerabilities/30257
2006-11-14
Published