[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-3871Date: (C)2019-06-19   (M)2023-12-22


A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 6.5
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
BID-107491
https://seclists.org/bugtraq/2019/Apr/8
DSA-4424
FEDORA-2019-9993d32c48
FEDORA-2019-b85d4171d4
https://lists.debian.org/debian-lts-announce/2019/03/msg00039.html
http://www.openwall.com/lists/oss-security/2019/03/18/4
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3871
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-03.html
openSUSE-SU-2019:1128

CWE    1
CWE-20
OVAL    7
oval:org.secpod.oval:def:54390
oval:org.secpod.oval:def:116162
oval:org.secpod.oval:def:116944
oval:org.secpod.oval:def:116813
...

© SecPod Technologies