cbcvebase.

Debian Pdns vulnerabilities

35 known vulnerabilities affecting debian/pdns.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM15LOW7

Vulnerabilities

Page 2 of 2
CVE-2018-14626P3MEDIUMCVSS 5.3fixed in pdns 4.1.5-1 (bookworm)2018
CVE-2018-14626 [MEDIUM] CVE-2018-14626: pdns - PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor ... PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service. Scope: local bookworm: resolved (fixed in 4.1.5-1) bullseye: resolved (fixed in 4.1.5-1) forky: resolved (fixed in 4.1.5-1) sid: resolved (fixed in 4.1.5-1) trixie:
debian
CVE-2008-3337P4LOWCVSS 6.8fixed in pdns 2.9.21.1-1 (bookworm)2008
CVE-2008-3337 [MEDIUM] CVE-2008-3337: pdns - PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which mig... PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217. Scope: local bookworm: resolved (fixed in 2.9.21.1-1) bullseye: resolved (fixed in 2.9.21.1-1) forky: resolved (fixed in 2.9.21.1-1
debian
CVE-2016-6172P4MEDIUMCVSS 6.8fixed in pdns 4.0.1-1 (bookworm)2016
CVE-2016-6172 [MEDIUM] CVE-2016-6172: pdns - PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS ... PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response. Scope: local bookworm: resolved (fixed in 4.0.1-1) bullseye: resolved (fixed in 4.0.1-1) forky: resolved (fixed in 4.0.1-1) sid: resolved (fixed in 4.0.1-1) tri
debian
CVE-2016-7073P4MEDIUMCVSS 5.3fixed in pdns 4.0.2-1 (bookworm)2016
CVE-2016-7073 [MEDIUM] CVE-2016-7073: pdns - An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recurs... An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack. Scope: local bookw
debian
CVE-2016-7074P4MEDIUMCVSS 5.3fixed in pdns 4.0.2-1 (bookworm)2016
CVE-2016-7074 [MEDIUM] CVE-2016-7074: pdns - An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recurs... An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not covered by the TSIG
debian
CVE-2012-0206P4HIGHCVSS 5.0fixed in pdns 3.0-1.1 (bookworm)2012
CVE-2012-0206 [MEDIUM] CVE-2012-0206: pdns - common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 an... common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response. Scope: local bookworm: resolved (fixed in 3.0-1.1) bullseye: resolved (fixed in 3.0-1.1) forky: resolved (fixed in 3.0-1.1) sid: resolved (fixed in 3.0-1.1) trixie: resolved
debian
CVE-2005-0038P4MEDIUMCVSS 5.0fixed in pdns 2.9.17-1 (bookworm)2005
CVE-2005-0038 [MEDIUM] CVE-2005-0038: pdns - The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to... The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop. Scope: local bookworm: resolved (fixed in 2.9.17-1) bullseye: resolved (fixed in 2.9.17-1) forky: resolved (fixed in 2.9.17-1) sid: resolved (fixed
debian
CVE-2020-17482P4MEDIUMCVSS 4.3fixed in pdns 4.3.1-1 (bookworm)2020
CVE-2020-17482 [MEDIUM] CVE-2020-17482: pdns - An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an a... An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed in 4.3.1-1) tri
debian
CVE-2019-10203P4LOWCVSS 4.3fixed in pdns 4.2.0-1 (bookworm)2019
CVE-2019-10203 [MEDIUM] CVE-2019-10203: pdns - PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4... PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS. Scope: local bookworm: resolved (fixed in 4.2.0-1) bullseye: resolved (fixed in 4.2.0-1) forky: resolved (fixed in 4.2.0-1) sid: resolved (fixed in 4.2.0-1) trixie: resolved (fix
debian
CVE-2005-2301P4MEDIUMCVSS 5.0fixed in pdns 2.9.18-1 (bookworm)2005
CVE-2005-2301 [MEDIUM] CVE-2005-2301: pdns - PowerDNS before 2.9.18, when running with an LDAP backend, does not properly esc... PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack. Scope: local bookworm: resolved (fixed in 2.9.18-1) bullseye: resolved (fixed in 2.9.18-1) forky: resolved (fixed in 2.9.18-1) sid:
debian
CVE-2019-10163P4MEDIUMCVSS 4.3fixed in pdns 4.1.6-3 (bookworm)2019
CVE-2019-10163 [MEDIUM] CVE-2019-10163: pdns - A Vulnerability has been found in PowerDNS Authoritative Server before versions ... A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue. Scope: local bookworm: resolved (fi
debian
CVE-2008-5277P4LOWCVSS 4.3fixed in pdns 2.9.21.2-1 (bookworm)2008
CVE-2008-5277 [MEDIUM] CVE-2008-5277: pdns - PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (d... PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query. Scope: local bookworm: resolved (fixed in 2.9.21.2-1) bullseye: resolved (fixed in 2.9.21.2-1) forky: resolved (fixed in 2.9.21.2-1) sid: resolved (fixed in 2.9.21.2-1) trixie: resolved (fixed in 2.9.21.2-1)
debian
CVE-2006-4252P4LOWCVSS 5.0fixed in pdns-recursor 3.1.4-1 (bookworm)2006
CVE-2006-4252 [MEDIUM] CVE-2006-4252: pdns - PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of... PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2005-0428P4MEDIUMCVSS 5.0fixed in pdns 2.9.16-6 (bookworm)2005
CVE-2005-0428 [MEDIUM] CVE-2005-0428: pdns - The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows re... The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes. Scope: local bookworm: resolved (fixed in 2.9.16-6) bullseye: resolved (fixed in 2.9.16-6) forky: resolved (fixed in 2.9.16-6) sid: resolved (fixed in 2.9.16-6) trixie: resolved (fixed in 2.9.16-6)
debian
CVE-2005-2302P4MEDIUMCVSS 2.1fixed in pdns 2.9.18-1 (bookworm)2005
CVE-2005-2302 [LOW] CVE-2005-2302: pdns - PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addr... PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion. Scope: local bookworm: resolved (fixed in 2.9.18-1) bullseye: resolved (fixed in 2.9.18-1) forky: resolved (fixed in
debian
Debian Pdns vulnerabilities | cvebase