VDB

DEBIAN-CVE-2019-3806

DEBIAN-CVE-2019-3806 PUBLISHED CVSS 8.100000381469727 HIGH

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11pdns-recursor0, 0, 0
Debian:12pdns-recursor0, 0, 0
Debian:14pdns-recursor0, 0, 0
Debian:13pdns-recursor0, 0, 0

Timeline

  • Jan 29, 2019 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›