CVE-2023-22617

A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:powerdns:recursor:4.8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
Summary
  • (es) Un atacante remoto podría provocar una recursividad infinita en PowerDNS Recursor 4.8.0 a través de una consulta DNS que recupera registros DS para un dominio mal configurado, porque la minimización de QName se utiliza en el modo de reserva de QM. Esto se solucionó en 4.8.1.
References () http://www.openwall.com/lists/oss-security/2023/01/20/1 - Mailing List, Release Notes, Third Party Advisory () http://www.openwall.com/lists/oss-security/2023/01/20/1 - Mailing List, Release Notes, Third Party Advisory
References () https://docs.powerdns.com/recursor/changelog/4.8.html#change-4.8.1 - Release Notes, Vendor Advisory () https://docs.powerdns.com/recursor/changelog/4.8.html#change-4.8.1 - Release Notes, Vendor Advisory
References () https://docs.powerdns.com/recursor/security-advisories/ - Vendor Advisory () https://docs.powerdns.com/recursor/security-advisories/ - Vendor Advisory

Information

Published : 2023-01-21 19:15

Updated : 2025-04-03 15:15


NVD link : CVE-2023-22617

Mitre link : CVE-2023-22617

CVE.ORG link : CVE-2023-22617


JSON object : View

Products Affected

powerdns

  • recursor
CWE
CWE-674

Uncontrolled Recursion