CVE-2012-0206
published 2012-02-17CVE-2012-0206: common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.26%
91.7th percentile
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns 3.0-1.1 (bookworm) | pdns 3.0-1.1 (bookworm) |
| open-xchange | pdns | >= 0 < 3.0-1.1 | 3.0-1.1 |
| open-xchange | pdns | >= 0 < 3.0-1.1 | 3.0-1.1 |
| open-xchange | pdns | >= 0 < 3.0-1.1 | 3.0-1.1 |
| open-xchange | pdns | >= 0 < 3.0-1.1 | 3.0-1.1 |
| powerdns | authoritative_server | <= 2.9.22 | — |
| powerdns | authoritative_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fvg-fh8j-g524: common_startup
ghsa_unreviewed·2022-05-04
CVE-2012-0206 [MEDIUM] GHSA-4fvg-fh8j-g524: common_startup
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
OSV
CVE-2012-0206: common_startup
osv·2012-02-17·CVSS 5.0
CVE-2012-0206 [MEDIUM] CVE-2012-0206: common_startup
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
Debian
CVE-2012-0206: pdns - common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 an...
vendor_debian·2012·CVSS 5.0
CVE-2012-0206 [MEDIUM] CVE-2012-0206: pdns - common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 an...
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
Scope: local
bookworm: resolved (fixed in 3.0-1.1)
bullseye: resolved (fixed in 3.0-1.1)
forky: resolved (fixed in 3.0-1.1)
sid: resolved (fixed in 3.0-1.1)
trixie: resolved (fixed in 3.0-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
PowerDNS DoS Vulnerability
bugzilla·2012-01-09·CVSS 5.0
[MEDIUM] PowerDNS DoS Vulnerability
PowerDNS DoS Vulnerability
Description of problem:
From http://mailman.powerdns.com/pipermail/pdns-announce/2012-January/000151.html:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Dear PowerDNS users,
Tomorrow (Tuesday the 10th of January) at 9AM eastern time, 15:00 Central
European Time, we will be releasing an important PowerDNS Security Advisory.
This Advisory contains details of a Denial of Service issue within all
currently used versions of the PowerDNS Authoritative Server.
We will be releasing:
* A configuration based workaround, which might have a performance
penalty
* An iptables based workaround
* Versions 2.9.22.5 and 3.0.1 of the Authoritative Server
As source code
Packages (static 32 bit and 64 bit for Debian and RPM based
Linux distributions)
* A one-line patch that
Bugzilla
Denial of Service vulnerability in PowerDNS 2.9.22
bugzilla·2012-01-09·CVSS 5.0
[MEDIUM] Denial of Service vulnerability in PowerDNS 2.9.22
Denial of Service vulnerability in PowerDNS 2.9.22
http://mailman.powerdns.com/pipermail/pdns-announce/2012-January/000151.html says:
----
Tomorrow (Tuesday the 10th of January) at 9AM eastern time, 15:00 Central
European Time, we will be releasing an important PowerDNS Security Advisory.
This Advisory contains details of a Denial of Service issue within all
currently used versions of the PowerDNS Authoritative Server.
We will be releasing:
* A configuration based workaround, which might have a performance
penalty
* An iptables based workaround
* Versions 2.9.22.5 and 3.0.1 of the Authoritative Server
As source code
Packages (static 32 bit and 64 bit for Debian and RPM based
Linux distributions)
* A one-line patch that solves the issue for source based users
* Complete details of t
2012-02-17
Published