First published: Tue Jul 19 2005(Updated: )
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PowerDNS DNSDist | =2.9.6 | |
PowerDNS DNSDist | =2.9.12 | |
PowerDNS DNSDist | =2.9.7 | |
PowerDNS DNSDist | =2.9.1 | |
PowerDNS DNSDist | =2.9.17 | |
PowerDNS DNSDist | =2.9.10 | |
PowerDNS DNSDist | =2.9.2 | |
PowerDNS DNSDist | =2.9.8 | |
PowerDNS DNSDist | =2.9.0 | |
PowerDNS DNSDist | =2.9.11 | |
PowerDNS DNSDist | =2.9.16 | |
PowerDNS DNSDist | =2.9.13 | |
PowerDNS DNSDist | =2.9.5 | |
PowerDNS DNSDist | =2.9.4 | |
PowerDNS DNSDist | =2.9.3a | |
PowerDNS DNSDist | =2.9.14 | |
PowerDNS DNSDist | =2.9.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2302 is classified as a moderate severity vulnerability that affects PowerDNS versions before 2.9.18.
To fix CVE-2005-2302, you should upgrade PowerDNS to version 2.9.18 or later.
CVE-2005-2302 can cause a denial of service for clients that are allowed recursion, resulting in no answers being returned.
CVE-2005-2302 affects PowerDNS versions 2.9.0 through 2.9.17.
Users of PowerDNS who allow recursion from a restricted range of IP addresses are primarily impacted by CVE-2005-2302.