Denial of Service Vulnerability in PowerDNS Recursor by PowerDNS
CVE-2022-37428

6.5MEDIUM

Key Information:

Vendor
Powerdns
Status
Vendor
CVE Published:
23 August 2022

Summary

The PowerDNS Recursor versions up to and including 4.5.9, 4.6.2, and 4.7.1 are vulnerable to a denial of service due to improper cleanup when exceptions are thrown during execution. This vulnerability manifests when protobuf logging is enabled, causing the daemon to crash after processing a specifically crafted DNS query that triggers the issue. The affected system could be rendered inoperable, impacting DNS resolution capabilities and potentially disrupting services that rely on DNS.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.