CVE-2019-3806 PUBLISHED

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

EPSS 0.02% · 6.2th percentile

Risk Scores

EPSS Score
0.02%
6.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSpdns-recursor4.1.1-1build1, 4.0.6-1, 4.0.6-1build1
Ubuntu:Pro:16.04:LTSpdns-recursor4.0.0~alpha1-1, 4.0.0~alpha1-2, 4.0.0~alpha2-2

Timeline

References

Open in Interactive Console →