Input validation error in PowerDNS Recursor - CVE-2024-25583
Published: April 24, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input from an upstream server if recursive forwarding is configured. A remote attacker can send specially crafted DNS response to the server and perform a denial of service (DoS) attack.
Affected software
Debian Linux
pdns-recursor (Debian package)
How to mitigate CVE-2024-25583
pdns-recursor (Debian package) - update to 4.8.8-1