PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- <= 2.0.3
- <= 1.9.12
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions through 2.0.3 and 1.9.12. The issue arises from the internal web server, which is disabled by default but can be activated. When the web server is enabled, an attacker can send crafted HTTP requests that cause unlimited memory allocation, leading to a denial-of-service condition.
Exploitation of this vulnerability causes excessive memory consumption, which can lead to a denial-of-service condition by causing the application to become unresponsive or to crash.
Users can upgrade to PowerDNS DNSdist versions 1.9.13 or 2.0.4, where this vulnerability has been patched. Alternatively, the internal web server can be disabled or restricted to trusted clients.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.