Vulnerabilities > CVE-2022-37428 - Incomplete Cleanup vulnerability in multiple products
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://docs.powerdns.com/recursor/lua-config/protobuf.html
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-02.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXSREJKTT6RNE3GXQENQ4R4HS37UNSPX/
- https://docs.powerdns.com/recursor/lua-config/protobuf.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FXSREJKTT6RNE3GXQENQ4R4HS37UNSPX/
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-02.html