Unrated severityNVD Advisory· Published Aug 23, 2022· Updated Aug 3, 2024
CVE-2022-37428
CVE-2022-37428
Description
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
Affected products
4- PowerDNS/Recursordescription
- osv-coords3 versionspkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdns-recursor&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pdns-recursor&distro=SUSE%20Package%20Hub%2015%20SP4
< 4.6.3-bp154.2.3.1+ 2 more
- (no CPE)range: < 4.6.3-bp154.2.3.1
- (no CPE)range: < 4.7.2-1.1
- (no CPE)range: < 4.6.3-bp154.2.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXSREJKTT6RNE3GXQENQ4R4HS37UNSPX/mitrevendor-advisoryx_refsource_FEDORA
- docs.powerdns.com/recursor/lua-config/protobuf.htmlmitrex_refsource_MISC
- docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-02.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.