Logo
componentpdns-recursor
Name
pdns-recursor
Version
5.2.5-r1
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:powerdns:recursor:5.2.5:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
5.2.5-r1

Patches#


#
Title
Author
Resolve
1
Openwrt: don't search for boost libs in host dirs
Eneas U de Queiroz <cotequeiroz@gmail.com>
2
Patch #2
Unknown
3
Patch #3
Unknown

Vulnerabilities#


Name
Analysis
Description
Exploitable
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
Exploitable
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
Exploitable
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
Exploitable
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
Exploitable
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Exploitable
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.
Exploitable
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
Exploitable
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Exploitable
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Exploitable
Crafted zones can lead to increased incoming network traffic.
Exploitable
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
Exploitable
Crafted delegations or IP fragments can poison cached delegations in Recursor.
Exploitable
Crafted delegations or IP fragments can poison cached delegations in Recursor.