CVE-2018-1000003: Input Validation
Published Jan 22, 2018
·Updated
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
Affected Software
1 affected component
powerdns recursor=4.1.0
Event History
Jan 22, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1000003.
2
What is the severity of CVE-2018-1000003?
The severity of CVE-2018-1000003 is medium with a severity value of 3.7.
3
What software is affected by CVE-2018-1000003?
PowerDNS Recursor version 4.1.0 is affected by CVE-2018-1000003.
4
What does CVE-2018-1000003 allow an attacker to do?
CVE-2018-1000003 allows an attacker in a man-in-the-middle position to deny the existence of some data in DNS via packet replay.
5
Is there a fix for CVE-2018-1000003?
Yes, there is a fix available. Please refer to the PowerDNS security advisory at https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-01.html for more information.