CVE-2022-27227: High severity powerdns vulnerability
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-27227?
CVE-2022-27227 is a vulnerability in PowerDNS Authoritative Server and PowerDNS Recursor that allows incomplete zone transfers to be handled as successful transfers.
Which software versions are affected by CVE-2022-27227?
PowerDNS Authoritative Server versions before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1, as well as PowerDNS Recursor versions before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1 are affected by CVE-2022-27227.
How severe is CVE-2022-27227?
CVE-2022-27227 has a severity rating of 7.5 (high).
How can I fix CVE-2022-27227?
To fix CVE-2022-27227, update PowerDNS Authoritative Server to version 4.4.3 or later, 4.5.x to version 4.5.4 or later, and 4.6.x to version 4.6.1 or later. For PowerDNS Recursor, update to version 4.4.8 or later for 4.4.x, 4.5.x to version 4.5.8 or later, and 4.6.x to version 4.6.1 or later.
Where can I find more information about CVE-2022-27227?
You can find more information about CVE-2022-27227 at the following references: [link1], [link2], [link3].