CVE-2012-0206
UnknownEPSS 5.26%
Last modified
CVE-2012-0206 is a vulnerability of currently unknown severity. common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.. EPSS estimates a 5.26% chance of exploitation in the next 30 days.
Description
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Powerdns | Authoritative Server | <= 2.9.22 |
| Powerdns | Authoritative Server | 3.0 |
References
- http://doc.powerdns.com/changelog.htmlRelease Notes
- http://doc.powerdns.com/powerdns-advisory-2012-01.htmlPatch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=772570Issue Tracking
- http://doc.powerdns.com/changelog.htmlRelease Notes
- http://doc.powerdns.com/powerdns-advisory-2012-01.htmlPatch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=772570Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0206?
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
How severe is CVE-2012-0206?
Severity scoring for CVE-2012-0206 is pending analysis. The EPSS model estimates a 5.26% probability of exploitation in the next 30 days.
How do I fix CVE-2012-0206?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-0200The server in IBM solidDB 6.5 before Interim Fix 6 does not …
- CVE-2012-0201Stack-based buffer overflow in pcspref.dll in pcsws.exe in I…
- CVE-2012-0202Multiple stack-based buffer overflows in tm1admsd.exe in the…
- CVE-2012-0203Cross-site scripting (XSS) vulnerability in InfoSphere Metad…
- CVE-2012-0204Untrusted search path vulnerability in InfoSphere Import Exp…
- CVE-2012-0205InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM I…
- CVE-2012-0207The igmp_heard_query function in net/ipv4/igmp.c in the Linu…7.5
- CVE-2012-0208Unspecified vulnerability in the Oracle Grid Engine componen…
- CVE-2012-0209Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware We…
- CVE-2012-0210debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x be…
- CVE-2012-0211debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x be…
- CVE-2012-0212debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x be…
Are you affected by CVE-2012-0206?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
