CVE Vulnerabilities

CVE-2012-1193

Published: Feb 17, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Affected Software

NameVendorStart VersionEnd Version
Powerdns_recursorPowerdns3.3 (including)3.3 (including)
Pdns-recursorUbuntuhardy*
Pdns-recursorUbuntulucid*
Pdns-recursorUbuntumaverick*
Pdns-recursorUbuntunatty*
Pdns-recursorUbuntuoneiric*
Pdns-recursorUbuntuprecise*
Pdns-recursorUbuntuquantal*
Pdns-recursorUbunturaring*
Pdns-recursorUbuntusaucy*
Pdns-recursorUbuntuupstream*
Pdns-recursorUbuntuutopic*

References