PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- <= 2.0.3
- <= 1.9.12
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions through 2.0.3 and 1.9.12. This issue arises from a divide-by-zero error that can be triggered by a client sending a crafted DNSCrypt query, leading to a crash.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the DNSdist service.
Users can upgrade to PowerDNS DNSdist versions 1.9.13 or 2.0.4, or disable DNSCrypt.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.