PT-2024-10518 · Powerdns+2 · Powerdns Recursor+2
Toshifumi Sakaguchi
·
Published
2024-10-03
·
Updated
2025-08-14
·
CVE-2024-25590
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PowerDNS Recursor versions prior to 4.9.9
PowerDNS Recursor versions prior to 5.0.9
PowerDNS Recursor versions prior to 5.1.2
Description
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service. The issue is related to insufficient input validation in the PowerDNS Recursor.
Recommendations
For PowerDNS Recursor versions prior to 4.9.9, update to version 4.9.9 or later.
For PowerDNS Recursor versions prior to 5.0.9, update to version 5.0.9 or later.
For PowerDNS Recursor versions prior to 5.1.2, update to version 5.1.2 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Powerdns Recursor
Red Os