CVE-2019-3806
Summary
| CVE | CVE-2019-3806 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-29 17:29:00 UTC |
| Updated | 2020-10-19 17:45:00 UTC |
| Description | An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PowerDNS Security Advisory 2019-01: Lua hooks are not applied in certain configurations — PowerDNS Recursor documentation | CONFIRM | docs.powerdns.com | Vendor Advisory |
| 1669421 – (CVE-2019-3806) CVE-2019-3806 pdns-recursor: Lua hooks are not applied in certain configuration | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.