HIGH
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length
Published Nov 14, 2006
7.5
HIGHCVSS 2.0
EPSS 8.50%
Description
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.
Affected products
No data.
OR
- ≤ 3.1.3
- 2.0_rc1
- 2.8
- 2.9.15
- 2.9.16
- 2.9.17
- 2.9.18
- 3.0
- 3.0.1
- 3.1
- 3.1.1
- 3.1.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://doc.powerdns.com/powerdns-advisory-2006-01.html x_refsource_CONFIRMPatchVendor Advisory
- http://lists.suse.com/archive/suse-security-announce/2006-Nov/0007.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/22824 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/22903 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22976 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2006/dsa-1211 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/21037 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/4484 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30270 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://doc.powerdns.com/powerdns-advisory-2006-01.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://lists.suse.com/archive/suse-security-announce/2006-Nov/0007.html | vendor-advisoryx_refsource_SUSE | |
| http://secunia.com/advisories/22824 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://secunia.com/advisories/22903 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/22976 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2006/dsa-1211 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/21037 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2006/4484 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/30270 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Nov 14, 2006
Updated Aug 7, 2024
Reserved Aug 21, 2006
Link CVE-2006-4251
CISA Vulnrichment
Updated n/a