Several significant security vulnerabilities have been identified and patched in PowerDNS, a widely used open-source nameserver known for its high performance, flexibility, and scalability.
It serves as an alternative to traditional DNS solutions like BIND and is widely used in both small-scale and large-scale DNS deployments.
These vulnerabilities, which affect both the PowerDNS Authoritative Server and PowerDNS Recursor, could expose systems to potential threats such as denial of service (DoS) attacks, arbitrary code execution, and data leaks.
The vulnerabilities impact multiple versions of Ubuntu, including Ubuntu 22.04 LTS, 20.04 LTS, 18.04 ESM, and 16.04 ESM. The affected packages are:
Below is a detailed breakdown of the identified vulnerabilities:
| CVE ID | Description | Impact | Affected Components |
|---|---|---|---|
| CVE-2018-1046 | Memory management issue in PowerDNS Authoritative Server could allow attackers to execute arbitrary code. | Arbitrary Code Execution | Authoritative Server |
| CVE-2018-10851 | Improper memory handling in PowerDNS Authoritative Server and Recursor could enable denial of service. | Denial of Service (DoS) | Authoritative Server, Recursor |
| CVE-2018-14626 | Flawed request validation after caching malformed input could lead to denial of service attacks. | Denial of Service (DoS) | Authoritative Server, Recursor |
| CVE-2018-14644 | Mishandling of cached malformed input in PowerDNS Recursor could cause denial of service. | Denial of Service (DoS) | Recursor |
| CVE-2020-17482 | Memory handling issue in PowerDNS Authoritative Server could expose sensitive information. | Information Disclosure | Authoritative Server |
| CVE-2022-27227 | Insufficient validation of IXFR requests could result in incomplete zone transfers being treated as valid. | Denial of Service (DoS) | Authoritative Server, Recursor |
This table provides a concise overview of the vulnerabilities, their potential impacts, and the affected components.
Users are strongly encouraged to update their systems to mitigate these vulnerabilities. The patched versions of the affected packages are available through Ubuntu Pro, a service providing extended security maintenance (ESM) and coverage for up to 25,000 packages in the Main and Universe repositories.
pdns-recursor: 4.6.0-1ubuntu1+esm1pdns-server: 4.5.3-1ubuntu0.1~esm1pdns-tools: 4.5.3-1ubuntu0.1~esm1pdns-recursor: 4.2.1-1ubuntu0.1~esm1pdns-server: 4.2.1-1ubuntu0.1~esm1pdns-tools: 4.2.1-1ubuntu0.1~esm1pdns-recursor: 4.1.1-2ubuntu0.1~esm1pdns-server: 4.1.1-1ubuntu0.1~esm1pdns-tools: 4.1.1-1ubuntu0.1~esm1pdns-recursor: 4.0.0~alpha2-2ubuntu0.1+esm1pdns-server: 4.0.0~alpha2-3ubuntu0.1~esm1pdns-tools: 4.0.0~alpha2-3ubuntu0.1~esm1A standard system update will automatically apply these changes.
Ubuntu Pro is available for free on up to five machines, offering extended security coverage for ten years. The service ensures ongoing protection for a wide range of open-source packages, reducing your system’s exposure to vulnerabilities.
System administrators are advised to prioritize these updates to safeguard their systems. Exploiting the disclosed vulnerabilities could disrupt critical services or compromise sensitive data.
Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…