CVE-2022-37428

Name
CVE-2022-37428
Description
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-02.html
MISC https://docs.powerdns.com/recursor/lua-config/protobuf.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXSREJKTT6RNE3GXQENQ4R4HS37UNSPX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXSREJKTT6RNE3GXQENQ4R4HS37UNSPX/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= 4.5.0 < 4.5.10
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= 4.6.0 < 4.6.3
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:* recursor >= 4.7.0 < 4.7.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
pdns-recursor 3.16-community 4.6.3-r0 Peter van Dijk <peter.van.dijk@powerdns.com> fixed