CVE-2018-10851: High severity powerdns vulnerability
Last updated 14 January 2025
Other sources
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10851?
CVE-2018-10851 is a vulnerability in PowerDNS Authoritative Server and PowerDNS Recursor that can lead to a remote denial of service.
Which versions of PowerDNS Authoritative Server are affected by CVE-2018-10851?
PowerDNS Authoritative Server versions 3.3.0 up to 4.1.4 (excluding 4.1.5 and 4.0.6) are affected by CVE-2018-10851.
Which versions of PowerDNS Recursor are affected by CVE-2018-10851?
PowerDNS Recursor versions 3.2 up to 4.1.4 (excluding 4.1.5 and 4.0.9) are affected by CVE-2018-10851.
How severe is CVE-2018-10851?
CVE-2018-10851 has a severity rating of 7.5 (high).
How can I fix CVE-2018-10851?
To fix CVE-2018-10851, update your PowerDNS Authoritative Server and PowerDNS Recursor to versions 4.1.5 or 4.0.6 for the Authoritative Server, and versions 4.1.5 or 4.0.9 for the Recursor.