PT-2024-12161 · Unknown · Technitium

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2023-28451

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Technitium version 11.0.2
Description An issue was discovered in the DNS resolving software, which triggers a resolver to ignore valid responses, thus causing a denial of service for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
Recommendations For Technitium version 11.0.2, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-28451

Affected Products

Technitium