CVE Vulnerabilities

CVE-2019-3806

Published: Jan 29, 2019 | Modified: Oct 19, 2020
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

Affected Software

Name Vendor Start Version End Version
Recursor Powerdns 4.1.4 (including) 4.1.9 (excluding)
Pdns-recursor Ubuntu bionic *
Pdns-recursor Ubuntu cosmic *
Pdns-recursor Ubuntu trusty *
Pdns-recursor Ubuntu upstream *
Pdns-recursor Ubuntu xenial *

References