CVE-2017-15094
Last modified
CVE-2017-15094 is a vulnerability of currently unknown severity. An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default).. EPSS estimates a 3.37% chance of exploitation in the next 30 days.
Description
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Powerdns | Recursor | >= 4.0.0, <= 4.0.6 |
References
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.htmlMitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.htmlMitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15094?
How severe is CVE-2017-15094?
How do I fix CVE-2017-15094?
Are you affected by CVE-2017-15094?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
