CVE-2019-3871
published 2019-03-21CVE-2019-3871: A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
12.63%
95.8th percentile
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns 4.1.6-2 (bookworm) | pdns 4.1.6-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| open-xchange | pdns | >= 0 < 4.1.6-2 | 4.1.6-2 |
| open-xchange | pdns | >= 0 < 4.1.6-2 | 4.1.6-2 |
| open-xchange | pdns | >= 0 < 4.1.6-2 | 4.1.6-2 |
| open-xchange | pdns | >= 0 < 4.1.6-2 | 4.1.6-2 |
| powerdns | authoritative_server | < 4.0.7 | 4.0.7 |
| powerdns | authoritative_server | >= 4.1.0 < 4.1.7 | 4.1.7 |
| the_powerdns_project | pdns | — | — |
| the_powerdns_project | pdns | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-3871: pdns - A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and befo...
vendor_debian·2019·CVSS 6.5
CVE-2019-3871 [MEDIUM] CVE-2019-3871: pdns - A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and befo...
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response
Scope: local
bookworm: resolved (fixed in 4.1.6-2)
bullseye: resolved (fixed in 4.1.6-2)
forky: resolved (fixed in 4.1.6-2)
sid: resolved (fixed in 4.1.6-2)
trixie: resolved (fixed in 4.1.6-2)
GHSA
GHSA-mg3r-wf83-7hqh: A vulnerability was found in PowerDNS Authoritative Server before 4
ghsa_unreviewed·2022-05-14
CVE-2019-3871 [HIGH] CWE-20 GHSA-mg3r-wf83-7hqh: A vulnerability was found in PowerDNS Authoritative Server before 4
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response
OSV
CVE-2019-3871: A vulnerability was found in PowerDNS Authoritative Server before 4
osv·2019-03-21·CVSS 8.8
CVE-2019-3871 [HIGH] CVE-2019-3871: A vulnerability was found in PowerDNS Authoritative Server before 4
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [fedora-all]
bugzilla·2019-03-19·CVSS 6.5
CVE-2019-3871 [MEDIUM] CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [fedora-all]
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [epel-all]
bugzilla·2019-03-19·CVSS 6.5
CVE-2019-3871 [MEDIUM] CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [epel-all]
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query
bugzilla·2019-03-14·CVSS 6.5
CVE-2019-3871 [MEDIUM] CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query
CVE-2019-3871 pdns: insufficient validation of data when building a HTTP request from a DNS query
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response
Upstream bug:
https://github.com/PowerDNS/pdns/issues/7573
Upstream Patch:
https://github.com/PowerDNS/pdns/pull/7576
Discussion:
External References:
https://doc.powerdns.com/authoritative/security-a
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00022.htmlhttp://www.openwall.com/lists/oss-security/2019/03/18/4http://www.securityfocus.com/bid/107491https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3871https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWUHF6MRSQ3YO7UUISGLV7MXCAGBW2VD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROFI6OTWF4GKONNSNEDUCW6LVSSEBZNF/https://seclists.org/bugtraq/2019/Apr/8https://www.debian.org/security/2019/dsa-4424http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00022.htmlhttp://www.openwall.com/lists/oss-security/2019/03/18/4http://www.securityfocus.com/bid/107491https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3871https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWUHF6MRSQ3YO7UUISGLV7MXCAGBW2VD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROFI6OTWF4GKONNSNEDUCW6LVSSEBZNF/https://seclists.org/bugtraq/2019/Apr/8https://www.debian.org/security/2019/dsa-4424
2019-03-21
Published