CVE-2006-2076: Medium severity pdnsd pdnsd vulnerability
Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote attackers to cause a denial of service (memory consumption) via a DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated by the OUSPG PROTOS DNS test suite.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2076?
CVE-2006-2076 is considered a high severity vulnerability due to its potential to cause denial of service through excessive memory consumption.
How do I fix CVE-2006-2076?
To fix CVE-2006-2076, you should upgrade to pdnsd version 1.2.4 or later, which addresses the memory leak issue.
What types of DNS queries are affected by CVE-2006-2076?
CVE-2006-2076 is triggered by DNS queries that utilize unsupported QTYPE or QCLASS values.
Which versions of pdnsd are vulnerable to CVE-2006-2076?
Versions of pdnsd prior to version 1.2.4, including 1.0.13 through 1.2.3_par, are vulnerable to CVE-2006-2076.
What are the potential impacts of CVE-2006-2076 on my system?
The potential impacts of CVE-2006-2076 include system crashes and degraded performance due to memory exhaustion.