| Vulnerability Name: | CVE-2006-4251 (CCN-30270) | ||||||||||||
| Assigned: | 2006-11-13 | ||||||||||||
| Published: | 2006-11-13 | ||||||||||||
| Updated: | 2017-07-20 | ||||||||||||
| Summary: | Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length. This vulnerability is addressed in the following product release: PowerDNS, Recursor, 3.1.4 | ||||||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2006-4251 Source: CCN Type: PowerDNS Security Advisory 2006-01 Malformed TCP queries can lead to a buffer overflow which might be exploitable Source: CONFIRM Type: Patch, Vendor Advisory http://doc.powerdns.com/powerdns-advisory-2006-01.html Source: SUSE Type: UNKNOWN SUSE-SA:2006:070 Source: CCN Type: SA22824 PowerDNS Recursor Two Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 22824 Source: SECUNIA Type: UNKNOWN 22903 Source: SECUNIA Type: UNKNOWN 22976 Source: DEBIAN Type: UNKNOWN DSA-1211 Source: DEBIAN Type: DSA-1211 pdns -- buffer overflow Source: CCN Type: OSVDB ID: 30334 PowerDNS Recursor TCP DNS Query Length Overflow Source: CCN Type: PowerDNS Web site Downloads Source: BID Type: Patch 21037 Source: CCN Type: BID-21037 PowerDNS Remote Denial of Service and Buffer Overflow Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-4484 Source: XF Type: UNKNOWN powerdns-dns-bo(30270) Source: XF Type: UNKNOWN powerdns-dns-bo(30270) Source: SUSE Type: SUSE-SA:2006:070 pdns remote denial of service problem | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||