vulnerability

FreeBSD: VID-f6d6308a-f2ec-11e8-b005-6805ca2fa271 (CVE-2018-16855): powerdns-recursor -- Crafted query can cause a denial of service

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Dec 9, 2018
Added
Dec 10, 2018
Modified
Dec 10, 2025

Description

powerdns Team reports: CVE-2018-16855: An issue has been found in PowerDNS Recursor where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash. When the PowerDNS Recursor is run inside a supervisor like supervisord or systemd, a crash will lead to an automatic restart, limiting the impact to a somewhat degraded service.

Solution

freebsd-upgrade-package-powerdns-recursor
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.