CVE-2018-14626Uncontrolled Resource Consumption in Authoritative

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.0%
top 87.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateJan 14

Description

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDpowerdns/recursor4.0.04.1.4
NVDpowerdns/authoritative4.1.04.1.4
CVEListV5the_powerdns_project/pdns-recursor4.0.0 to 4.1.4 inclusive
CVEListV5the_powerdns_project/pdns4.1.0 to 4.1.4 inclusive
Debianopen-xchange/pdns< 4.1.5-1+3

🔴Vulnerability Details

4
OSV
pdns, pdns-recursor vulnerabilities2025-01-14
GHSA
GHSA-pvqq-mpxw-8x79: PowerDNS Authoritative Server 42022-05-13
OSV
CVE-2018-14626: PowerDNS Authoritative Server 42018-11-29
CVEList
CVE-2018-14626: PowerDNS Authoritative Server 42018-11-29

📋Vendor Advisories

2
Ubuntu
PowerDNS vulnerabilities2025-01-14
Debian
CVE-2018-14626: pdns - PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor ...2018

💬Community

3
Bugzilla
CVE-2018-14626 pdns: Packet cache pollution via crafted query [fedora-all]2018-11-12
Bugzilla
CVE-2018-14626 pdns: Packet cache pollution via crafted query [epel-all]2018-11-12
Bugzilla
CVE-2018-14626 pdns: Packet cache pollution via crafted query2018-11-12
CVE-2018-14626 — Uncontrolled Resource Consumption | cvebase