VulnerabilityModified
CVE-2017-15094
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys.
MEDIUM 5.9EPSS 3.30%
Does this matter?
Lower severity and a low EPSS score (3.30%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default).
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.30% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401, CWE-772
- Affected
- powerdns/recursor
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.htmlMitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.htmlMitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.