cbcvebase.
CVE-2018-14626
published 2018-11-29

CVE-2018-14626: PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
debianpdns-recursor< pdns 4.1.5-1 (bookworm)pdns 4.1.5-1 (bookworm)
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.1.5-14.1.5-1
open-xchangepdns>= 0 < 4.0.0~alpha2-3ubuntu0.1~esm14.0.0~alpha2-3ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.1.1-1ubuntu0.1~esm14.1.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.2.1-1ubuntu0.1~esm14.2.1-1ubuntu0.1~esm1
open-xchangepdns>= 0 < 4.5.3-1ubuntu0.1~esm14.5.3-1ubuntu0.1~esm1
powerdnsauthoritative4.1.0 – 4.1.4
powerdnsrecursor4.0.0 – 4.1.4
the_powerdns_projectpdns
the_powerdns_projectpdns-recursor
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1
the_powerdns_projectpdns-recursor>= 0 < 4.1.7-14.1.7-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH