CVE-2009-4009: Buffer Overflow

Published Jan 4, 2010
·
Updated

Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.

Other sources

CVE-2009-4009, CVE-2009-4010 This Wednesday the release of the PowerDNS Recursor 3.1.7.2 will be made public, which fixes two important security issues, one of which is remotely exploitable. Given the critical nature of these vulnerabilities, we are trying to keep details confidential for a few more days. Summary ------- The short version: please contact me off-list if you distribute the PowerDNS Recursor (any version), and if you want to gain early access to version 3.1.7.2 and associated release notes. Details ------- The two security issues have been discovered by two parties which we cannot yet publicly mention or thank, but they deserve full credit and gratitude for their discoveries. Two CVE numbers have been requested, they will be communicated ASAP. One issue is remotely exploitable, and there are no configuration countermeasures. The other allows a (skilled) attacker to spoof domain data for domain names he does not own. The first issue is at least a DoS, but in all likelihood can be expanded into a full compromise ('rooted'). The release that will be made public is already available for distributors. Other good news is that it is already serving over a million ISP customers, with no apparent problems. Contact me off-list for quick access to the new PowerDNS Recursor code, patch & release notes. If you need any kind of assistance in doing a smooth upgrade, also do not hesitate to contact me.

Red Hat

Affected Software

19 affected componentsFixes available
redhat/3.1.7.2<1.el5
1.el5
powerdns recursor=3.1.7
powerdns recursor=3.1
powerdns recursor=2.9.18
powerdns recursor=2.0_rc1
powerdns recursor=3.1.2
powerdns recursor=3.0
powerdns recursor=2.9.15
powerdns recursor=3.1.5
powerdns recursor=3.1.1
powerdns recursor=3.0.1
powerdns recursor<=3.1.7.2
powerdns recursor=2.9.17
powerdns recursor=3.1.7.1
powerdns recursor=2.8
powerdns recursor=3.1.3
powerdns recursor=2.9.16
powerdns recursor=3.1.4
powerdns recursor=3.1.6

Remediation

Event History

Jan 8, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2009-4009?

CVE-2009-4009 is classified as a critical vulnerability that can lead to remote code execution.

2

How do I fix CVE-2009-4009?

To remedy CVE-2009-4009, upgrade to PowerDNS Recursor version 3.1.7.2 or later.

3

What versions of PowerDNS are affected by CVE-2009-4009?

PowerDNS Recursor versions up to 3.1.7.1 are affected by CVE-2009-4009.

4

Is CVE-2009-4009 related to other vulnerabilities?

Yes, CVE-2009-4009 is associated with CVE-2009-4010 as part of a security release.

5

What is the impact of CVE-2009-4009 if exploited?

Exploitation of CVE-2009-4009 can allow an attacker to execute arbitrary code on the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203