CVE-2008-4194: Medium severity pdnsd vulnerability
Published Sep 24, 2008
·Updated
The pexecquery function in src/dnsquery.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."
Affected Software
16 affected components
pdnsd pdnsd=1.1.8b1-par5
pdnsd pdnsd=1.2-par
pdnsd pdnsd=1.2.4-par
pdnsd pdnsd=1.2.5-par
pdnsd pdnsd=1.2.1_par
pdnsd pdnsd=1.1.7a
pdnsd pdnsd=1.1.9-par
pdnsd pdnsd=1.1.11-par
pdnsd pdnsd=1.1.8b1-par8
pdnsd pdnsd=1.1.8b1-par7
pdnsd pdnsd=1.1.8b1-par6
pdnsd pdnsd=1.1.11a-par
pdnsd pdnsd<=1.2.6-par
pdnsd pdnsd=1.1.10-par
pdnsd pdnsd=1.1.7
pdnsd pdnsd=1.1.8b1-par4
Event History
Sep 24, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4194?
CVE-2008-4194 has a high severity level because it can lead to a denial of service through daemon crashes.
2
How do I fix CVE-2008-4194?
To fix CVE-2008-4194, upgrade to pdnsd version 1.2.7-par or later.
3
What software is affected by CVE-2008-4194?
CVE-2008-4194 affects pdnsd versions before 1.2.7-par, including versions 1.1.8b1-par5 to 1.2.6-par.
4
What type of vulnerability is CVE-2008-4194?
CVE-2008-4194 is a denial of service vulnerability caused by a dangling pointer bug.
5
Can CVE-2008-4194 be exploited remotely?
Yes, CVE-2008-4194 can be exploited remotely by sending a long DNS reply with multiple entries.