CVE Vulnerabilities

CVE-2005-2301

Published: Jul 19, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.

Affected Software

NameVendorStart VersionEnd Version
PowerdnsPowerdns2.9.0 (including)2.9.0 (including)
PowerdnsPowerdns2.9.1 (including)2.9.1 (including)
PowerdnsPowerdns2.9.2 (including)2.9.2 (including)
PowerdnsPowerdns2.9.3a (including)2.9.3a (including)
PowerdnsPowerdns2.9.4 (including)2.9.4 (including)
PowerdnsPowerdns2.9.5 (including)2.9.5 (including)
PowerdnsPowerdns2.9.6 (including)2.9.6 (including)
PowerdnsPowerdns2.9.7 (including)2.9.7 (including)
PowerdnsPowerdns2.9.8 (including)2.9.8 (including)
PowerdnsPowerdns2.9.10 (including)2.9.10 (including)
PowerdnsPowerdns2.9.11 (including)2.9.11 (including)
PowerdnsPowerdns2.9.12 (including)2.9.12 (including)
PowerdnsPowerdns2.9.13 (including)2.9.13 (including)
PowerdnsPowerdns2.9.14 (including)2.9.14 (including)
PowerdnsPowerdns2.9.15 (including)2.9.15 (including)
PowerdnsPowerdns2.9.16 (including)2.9.16 (including)
PowerdnsPowerdns2.9.17 (including)2.9.17 (including)
PdnsUbuntudapper*
PdnsUbuntudevel*
PdnsUbuntuedgy*
PdnsUbuntufeisty*

References