Description
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages1 packages
🔴Vulnerability Details
3GHSAGHSA-2268-76c3-x85m: An issue has been found in PowerDNS Recursor from 4↗2022-05-13 ▶ CVEListCVE-2018-14644: An issue has been found in PowerDNS Recursor from 4↗2018-11-09 ▶ OSVCVE-2018-14644: An issue has been found in PowerDNS Recursor from 4↗2018-11-09 ▶ 📋Vendor Advisories
2UbuntuPowerDNS vulnerabilities↗2025-01-14 ▶ DebianCVE-2018-14644: pdns-recursor - An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1....↗2018 ▶ 💬Community
5BugzillaCVE-2018-14644 pdns-recursor: pdns: crafted query for meta-types can lead to a DoS [epel-all]↗2018-11-12 ▶ BugzillaCVE-2018-14644 pdns-recursor: pdns: crafted query for meta-types can lead to a DoS [fedora-all]↗2018-11-12 ▶ BugzillaCVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS [epel-all]↗2018-11-09 ▶ BugzillaCVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS [fedora-all]↗2018-11-09 ▶ BugzillaCVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS↗2018-11-09 ▶