CVE Vulnerabilities

CVE-2020-17482

Use of Uninitialized Resource

Published: Oct 02, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
AuthoritativePowerdns*4.3.1 (excluding)
PdnsUbuntubionic*
PdnsUbuntuesm-apps/bionic*
PdnsUbuntuesm-apps/focal*
PdnsUbuntuesm-apps/xenial*
PdnsUbuntufocal*
PdnsUbuntugroovy*
PdnsUbuntutrusty*
PdnsUbuntuupstream*
PdnsUbuntuxenial*

Potential Mitigations

References