CVE-2020-17482
Ubuntu Security Notice USN-7203-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
Se ha encontrado un problema en PowerDNS Authoritative Server versiones anteriores a 4.3.1, donde un usuario autorizado con la capacidad de insertar registros diseñados en una zona podría filtrar el contenido de la memoria no inicializada
Wei Hao discovered that PowerDNS Authoritative Server incorrectly handled memory when accessing certain files. An attacker could possibly use this issue to achieve arbitrary code execution. It was discovered that PowerDNS Authoritative Server and PowerDNS Recursor incorrectly handled memory when receiving certain remote input. An attacker could possibly use this issue to cause denial of service. Kees Monshouwer discovered that PowerDNS Authoritative Server and PowerDNS Recursor incorrectly handled request validation after having cached malformed input. An attacker could possibly use this issue to cause denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-11 CVE Reserved
- 2020-10-02 CVE Published
- 2024-08-04 CVE Updated
- 2025-06-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-908: Use of Uninitialized Resource
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/PowerDNS/pdns | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-05.html | 2022-01-01 | |
https://security.gentoo.org/glsa/202012-18 | 2022-01-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Powerdns Search vendor "Powerdns" | Authoritative Search vendor "Powerdns" for product "Authoritative" | < 4.3.1 Search vendor "Powerdns" for product "Authoritative" and version " < 4.3.1" | - |
Affected
|