cbcvebase.
CVE-2018-10851
published 2018-11-29

CVE-2018-10851: PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a…

PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.04%
92.6th percentile
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
debianpdns-recursor< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.0.0~alpha2-3ubuntu0.1~esm14.0.0~alpha2-3ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.1.1-1ubuntu0.1~esm14.1.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.2.1-1ubuntu0.1~esm14.2.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.5.3-1ubuntu0.1~esm14.5.3-1ubuntu0.1~esm1
powerdnsauthoritative3.3 – 4.1.4
powerdnsrecursor3.2 – 4.1.4
the_powerdns_projectpdns
the_powerdns_projectpdns-recursor
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.