Input validation error in PowerDNS - CVE-2019-3871

 

Input validation error in PowerDNS - CVE-2019-3871

Published: April 8, 2019


Vulnerability identifier: #VU18151
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3871
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing DNS requests in RESTful mode in the HTTP Connector of the Remote backend. A remote attacker can send a specially crafted DNS request to the affected server and perform denial of service (DoS) attack.


Affected software

PowerDNS
Arch Linux
Fedora
SUSE Linux
Opensuse
pdns (Alpine package)
pdns (Debian package)
pdns

How to mitigate CVE-2019-3871

Install updates from vendor's website.

PowerDNS - addressed in versions 4.0.7, 4.1.7
pdns (Alpine package) - addressed in versions 4.0.7-r0, 4.1.7-r0
pdns (Debian package) - update to 4.0.3-1+deb9u4
pdns - addressed in versions 4.1.7-1.el7, 4.1.7-1.fc28, 4.1.7-1.fc29, 4.1.7-1.fc30

External References

Related Security Bulletins