cbcvebase.
CVE-2018-10851
published 2018-11-29

CVE-2018-10851: PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a…

PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.04%
93.0th percentile
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
debianpdns-recursor< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.0.0~alpha2-3ubuntu0.1~esm14.0.0~alpha2-3ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.1.1-1ubuntu0.1~esm14.1.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.2.1-1ubuntu0.1~esm14.2.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.5.3-1ubuntu0.1~esm14.5.3-1ubuntu0.1~esm1
powerdnsauthoritative3.3 – 4.1.4—
powerdnsrecursor3.2 – 4.1.4—
the_powerdns_projectpdns——
the_powerdns_projectpdns-recursor——
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.