The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Powerdns_recursor | Powerdns | 3.3 (including) | 3.3 (including) |
Pdns-recursor | Ubuntu | hardy | * |
Pdns-recursor | Ubuntu | lucid | * |
Pdns-recursor | Ubuntu | maverick | * |
Pdns-recursor | Ubuntu | natty | * |
Pdns-recursor | Ubuntu | oneiric | * |
Pdns-recursor | Ubuntu | precise | * |
Pdns-recursor | Ubuntu | quantal | * |
Pdns-recursor | Ubuntu | raring | * |
Pdns-recursor | Ubuntu | saucy | * |
Pdns-recursor | Ubuntu | upstream | * |
Pdns-recursor | Ubuntu | utopic | * |