CVE-2008-5277
published 2008-12-09CVE-2008-5277: PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.38%
87.4th percentile
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns 2.9.21.2-1 (bookworm) | pdns 2.9.21.2-1 (bookworm) |
| open-xchange | pdns | >= 0 < 2.9.21.2-1 | 2.9.21.2-1 |
| open-xchange | pdns | >= 0 < 2.9.21.2-1 | 2.9.21.2-1 |
| open-xchange | pdns | >= 0 < 2.9.21.2-1 | 2.9.21.2-1 |
| open-xchange | pdns | >= 0 < 2.9.21.2-1 | 2.9.21.2-1 |
| powerdns | powerdns | <= 2.9.21.1 | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
| powerdns | powerdns | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-466m-36cm-ggv7: PowerDNS before 2
ghsa_unreviewed·2022-05-17
CVE-2008-5277 [MEDIUM] GHSA-466m-36cm-ggv7: PowerDNS before 2
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
OSV
CVE-2008-5277: PowerDNS before 2
osv·2008-12-09·CVSS 4.3
CVE-2008-5277 [MEDIUM] CVE-2008-5277: PowerDNS before 2
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
Red Hat
pdns: DoS (daemon crash) via a CH HINFO query.
vendor_redhat·2008-11-18·CVSS 4.3
CVE-2008-5277 [MEDIUM] pdns: DoS (daemon crash) via a CH HINFO query.
pdns: DoS (daemon crash) via a CH HINFO query.
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
Debian
CVE-2008-5277: pdns - PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (d...
vendor_debian·2008·CVSS 4.3
CVE-2008-5277 [MEDIUM] CVE-2008-5277: pdns - PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (d...
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
Scope: local
bookworm: resolved (fixed in 2.9.21.2-1)
bullseye: resolved (fixed in 2.9.21.2-1)
forky: resolved (fixed in 2.9.21.2-1)
sid: resolved (fixed in 2.9.21.2-1)
trixie: resolved (fixed in 2.9.21.2-1)
No detection rules found.
No public exploits indexed.
http://doc.powerdns.com/powerdns-advisory-2008-03.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://secunia.com/advisories/32979http://secunia.com/advisories/33264http://security.gentoo.org/glsa/glsa-200812-19.xmlhttp://securitytracker.com/id?1021304http://www.securityfocus.com/bid/32627https://exchange.xforce.ibmcloud.com/vulnerabilities/47076http://doc.powerdns.com/powerdns-advisory-2008-03.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.htmlhttp://secunia.com/advisories/32979http://secunia.com/advisories/33264http://security.gentoo.org/glsa/glsa-200812-19.xmlhttp://securitytracker.com/id?1021304http://www.securityfocus.com/bid/32627https://exchange.xforce.ibmcloud.com/vulnerabilities/47076
2008-12-09
Published