CVE-2008-4194 PUBLISHED CVSS 5 MEDIUM

The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."

EPSS 11.66% · 93.6th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
11.66%
93.6th percentile

Affected Products

VendorProductVersions
pdnsdpdnsd1.2.5-par, 0, 1.1.7
n/an/an/a

Timeline

References

Open in Interactive Console →