First published: Fri Oct 02 2020(Updated: )
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/pdns | 4.4.1-1 4.7.3-2 4.9.3-1 | |
PowerDNS | <4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17482 is an issue found in PowerDNS Authoritative Server before version 4.3.1, where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
CVE-2020-17482 has a severity value of 4.3, which is considered medium.
PowerDNS Authoritative Server versions up to, but not including, 4.3.1 are affected by CVE-2020-17482.
To fix CVE-2020-17482, it is recommended to update PowerDNS Authoritative Server to version 4.3.1 or later.
You can find more information about CVE-2020-17482 in the PowerDNS Advisory, GitHub repository, and Gentoo security advisory linked in the references section.