CVE-2018-14626: High severity powerdns vulnerability
Last updated 14 January 2025
Other sources
PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14626?
CVE-2018-14626 is a vulnerability in PowerDNS Authoritative Server and PowerDNS Recursor that allows packet cache pollution via a crafted query, leading to denial of service.
Which PowerDNS software versions are affected?
PowerDNS Authoritative Server versions 4.1.0 to 4.1.4 and PowerDNS Recursor versions 4.0.0 to 4.1.4 are affected.
What is the severity of CVE-2018-14626?
CVE-2018-14626 has a severity rating of high with a CVSS score of 7.5.
How can the vulnerability be exploited?
The vulnerability can be exploited by sending a crafted query to the vulnerable PowerDNS server, polluting the packet cache and causing denial of service.
Are there any patches or fixes available?
Yes, PowerDNS has released security advisories for both the PowerDNS Authoritative Server and PowerDNS Recursor, providing patches to address the vulnerability.