CVE-2018-14644Improper Input Validation in Recursor

Severity
5.9MEDIUMNVD
CNA5.3
EPSS
0.0%
top 94.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 9
Latest updateJan 14

Description

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDpowerdns/recursor4.0.04.1.4

🔴Vulnerability Details

3
GHSA
GHSA-2268-76c3-x85m: An issue has been found in PowerDNS Recursor from 42022-05-13
CVEList
CVE-2018-14644: An issue has been found in PowerDNS Recursor from 42018-11-09
OSV
CVE-2018-14644: An issue has been found in PowerDNS Recursor from 42018-11-09

📋Vendor Advisories

2
Ubuntu
PowerDNS vulnerabilities2025-01-14
Debian
CVE-2018-14644: pdns-recursor - An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1....2018

💬Community

5
Bugzilla
CVE-2018-14644 pdns-recursor: pdns: crafted query for meta-types can lead to a DoS [epel-all]2018-11-12
Bugzilla
CVE-2018-14644 pdns-recursor: pdns: crafted query for meta-types can lead to a DoS [fedora-all]2018-11-12
Bugzilla
CVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS [epel-all]2018-11-09
Bugzilla
CVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS [fedora-all]2018-11-09
Bugzilla
CVE-2018-14644 pdns: crafted query for meta-types can lead to a DoS2018-11-09
CVE-2018-14644 — Improper Input Validation in Recursor | cvebase