Dismissed
Permalink
CVE-2025-59029
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse dismissed
Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
Affected products
pdns-recursor
- <5.3.2
Matching in nixpkgs
pkgs.pdns-recursor
Recursive DNS server
Package maintainers
-
@rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>