PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- >= 1.9.0, <= 1.9.8
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions 1.9.0 prior to 1.9.8, when configured to provide DNS-over-HTTPS (DoH) via the nghttp2 provider. An attacker can craft a DoH exchange that triggers a double-free memory error, causing DNSdist to crash and disrupt service. This vulnerability does not affect PowerDNS DNSdist 1.9.9 or versions prior to 1.9.0.
Exploitation of this vulnerability leads to a crash of the DNSdist service, causing a denial-of-service condition.
Users are advised to upgrade to PowerDNS DNSdist version 1.9.9. Alternatively, the h2o provider can be used temporarily until the upgrade is completed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.