CVE-2017-15094

An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default).
Configurations

Configuration 1 (hide)

cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:14

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/101982 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101982 - Third Party Advisory, VDB Entry
References () https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.html - Mitigation, Patch, Vendor Advisory () https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-07.html - Mitigation, Patch, Vendor Advisory

Information

Published : 2018-01-23 15:29

Updated : 2024-11-21 03:14


NVD link : CVE-2017-15094

Mitre link : CVE-2017-15094

CVE.ORG link : CVE-2017-15094


JSON object : View

Products Affected

powerdns

  • recursor
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-772

Missing Release of Resource after Effective Lifetime