CVE Vulnerabilities

CVE-2012-1193

Published: Feb 17, 2012 | Modified: Dec 13, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a ghost domain names attack.

Affected Software

Name Vendor Start Version End Version
Powerdns_recursor Powerdns 3.3 (including) 3.3 (including)
Pdns-recursor Ubuntu hardy *
Pdns-recursor Ubuntu lucid *
Pdns-recursor Ubuntu maverick *
Pdns-recursor Ubuntu natty *
Pdns-recursor Ubuntu oneiric *
Pdns-recursor Ubuntu precise *
Pdns-recursor Ubuntu quantal *
Pdns-recursor Ubuntu raring *
Pdns-recursor Ubuntu saucy *
Pdns-recursor Ubuntu upstream *
Pdns-recursor Ubuntu utopic *

References