CVE-2019-3871Improper Input Validation in Authoritative Server

Severity
8.8HIGHNVD
CNA6.5
EPSS
0.0%
top 90.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 14

Description

A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDpowerdns/authoritative_server4.1.04.1.7+1
CVEListV5the_powerdns_project/pdns4.0.7, 4.1.7+1
Debianopen-xchange/pdns< 4.1.6-2+3

Also affects: Fedora 28, 29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mg3r-wf83-7hqh: A vulnerability was found in PowerDNS Authoritative Server before 42022-05-14
OSV
CVE-2019-3871: A vulnerability was found in PowerDNS Authoritative Server before 42019-03-21
CVEList
CVE-2019-3871: A vulnerability was found in PowerDNS Authoritative Server before 42019-03-21

📋Vendor Advisories

1
Debian
CVE-2019-3871: pdns - A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and befo...2019

💬Community

3
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [fedora-all]2019-03-19
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [epel-all]2019-03-19
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query2019-03-14
CVE-2019-3871 — Improper Input Validation | cvebase