Denial of Service Vulnerability in PowerDNS Recursor by PowerDNS
CVE-2022-37428
6.5MEDIUM
Summary
The PowerDNS Recursor versions up to and including 4.5.9, 4.6.2, and 4.7.1 are vulnerable to a denial of service due to improper cleanup when exceptions are thrown during execution. This vulnerability manifests when protobuf logging is enabled, causing the daemon to crash after processing a specifically crafted DNS query that triggers the issue. The affected system could be rendered inoperable, impacting DNS resolution capabilities and potentially disrupting services that rely on DNS.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved