Out-of-bounds read in PowerDNS Recursor - CVE-2018-16855
Published: November 28, 2018 / Updated: November 28, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds memory read while computing the hash of the query for a packet cache lookup. A remote attacker can send a specially crafted DNS query and cause the service to crash.
Affected software
Arch Linux
Fedora
Opensuse
pdns-recursor (Alpine package)
pdns-recursor
How to mitigate CVE-2018-16855
pdns-recursor (Alpine package) - update to 4.1.8-r0
pdns-recursor - addressed in versions 4.1.8-1.el7, 4.1.8-1.fc28, 4.1.8-1.fc29
External References
Related Security Bulletins
- Denial of service in PowerDNS Recursor
- Arch Linux update for powerdns-recursor
- OpenSUSE Linux update for pdns-recursor
- OpenSUSE Linux update for pdns-recursor
- OpenSUSE Linux update for pdns-recursor
- Out-of-bounds read in pdns-recursor (Alpine package)
- Fedora EPEL 7 update for pdns-recursor
- Fedora 28 update for pdns-recursor
- Fedora 29 update for pdns-recursor