← back
CVE-2018-16855highCWE-125

CVE-2018-16855

33Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 59%
exploitation probability
59%top 1% of all CVEs
observed exploitation
nono source reports it
In short

PowerDNS Recursor has a flaw where specially crafted DNS queries can cause the server to read memory it shouldn't access, potentially crashing it. This affects older versions before 4.1.8.

Technical detail

An out-of-bounds read vulnerability in PowerDNS Recursor's packet cache hash computation allows remote attackers to trigger memory access violations via malformed DNS queries. The vulnerability requires no authentication and can result in denial of service through application crash.

Summary generated and translated by AI from the official description.
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H