CVE-2022-27227

Name
CVE-2022-27227
Description
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-01.html
CONFIRM https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2022-01.html
MISC https://docs.powerdns.com/recursor/security-advisories/index.html
MISC https://doc.powerdns.com/authoritative/security-advisories/index.html
MLIST http://www.openwall.com/lists/oss-security/2022/03/25/1
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2QKN56VWXUVFOYGUN75N5IRNK66OHTHT/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HEABZA46XYEUWMGSY2GYYVHISBVWEHIO/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJSKICB67SPPEGNXCQLZVSWR6QGCN3KP/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPHOFNI7FKM5NNOVDOWO4TBXFAFICCUE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2QKN56VWXUVFOYGUN75N5IRNK66OHTHT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HEABZA46XYEUWMGSY2GYYVHISBVWEHIO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJSKICB67SPPEGNXCQLZVSWR6QGCN3KP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPHOFNI7FKM5NNOVDOWO4TBXFAFICCUE/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:* authoritative_server >= None < 4.4.3
cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:* authoritative_server >= 4.5.0 < 4.5.4
cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:* authoritative_server >= 4.6.0 < 4.6.1
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= None < 4.4.8
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= 4.5.0 < 4.5.8
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= 4.6.0 < 4.6.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
pdns-recursor 3.15-community 4.5.8-r0 Peter van Dijk <peter.van.dijk@powerdns.com> fixed
pdns 3.15-community 4.5.4-r0 Peter van Dijk <peter.van.dijk@powerdns.com> fixed