CVE-2009-4010: High severity powerdns vulnerability
Published Jan 8, 2010
·Updated
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
Affected Software
18 affected components
powerdns recursor=3.1.7
powerdns recursor=3.1
powerdns recursor=2.9.18
powerdns recursor=2.0_rc1
powerdns recursor=3.1.2
powerdns recursor=3.0
powerdns recursor=2.9.15
powerdns recursor=3.1.5
powerdns recursor=3.1.1
powerdns recursor=3.0.1
powerdns recursor<=3.1.7.2
powerdns recursor=2.9.17
powerdns recursor=3.1.7.1
powerdns recursor=2.8
powerdns recursor=3.1.3
powerdns recursor=2.9.16
powerdns recursor=3.1.4
powerdns recursor=3.1.6
Remediation
Patch Available
Event History
Jan 8, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4010?
CVE-2009-4010 is considered a medium severity vulnerability due to its potential to allow remote attackers to spoof DNS data.
2
How do I fix CVE-2009-4010?
To fix CVE-2009-4010, you should upgrade PowerDNS Recursor to version 3.1.7.2 or later.
3
What are the affected versions in CVE-2009-4010?
The affected versions in CVE-2009-4010 include PowerDNS Recursor versions 2.0_rc1, 2.8, 2.9.15 to 2.9.18, and 3.0 to 3.1.7.1.
4
What type of attack is possible with CVE-2009-4010?
CVE-2009-4010 allows remote attackers to perform DNS spoofing attacks by exploiting crafted zones.
5
Is CVE-2009-4010 a zero-day vulnerability?
CVE-2009-4010 is not classified as a zero-day vulnerability as it has been publicly disclosed and patched by the vendor.