PT-2018-10142 · Powerdns+4 · Powerdns Recursor+5
Pedro Sampaio
·
Published
2018-11-29
·
Updated
2025-01-14
·
CVE-2018-10851
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PowerDNS Authoritative Server versions 3.3.0 through 4.1.4
PowerDNS Recursor versions 3.2 through 4.1.4
Description
The issue is related to a memory leak that occurs when parsing malformed records, which can lead to a remote denial of service.
Recommendations
For PowerDNS Authoritative Server versions 3.3.0 through 4.1.4, update to version 4.1.5 or later to resolve the issue.
For PowerDNS Recursor versions 3.2 through 4.1.4, update to version 4.1.5 or later to resolve the issue.
Fix
DoS
Missing Release of Resource after Effective Lifetime
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Powerdns Authoritative Server
Powerdns Recursor
Suse
Ubuntu