PowerDNS Recursor Remote Cache Poisoning Vulnerability
BID:37653
Info
PowerDNS Recursor Remote Cache Poisoning Vulnerability
| Bugtraq ID: | 37653 |
| Class: | Design Error |
| CVE: |
CVE-2009-4010 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2010 12:00AM |
| Updated: | Apr 13 2015 09:54PM |
| Credit: | An anonymous researcher reported this issue to the vendor |
| Vulnerable: |
S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 PowerDNS PowerDNS 3.1.7 .1 PowerDNS PowerDNS 3.1.7 PowerDNS PowerDNS 3.1.6 PowerDNS PowerDNS 3.1.5 PowerDNS PowerDNS 3.1.4 PowerDNS PowerDNS 3.1.3 PowerDNS PowerDNS 3.1.2 PowerDNS PowerDNS 3.1.1 PowerDNS PowerDNS 3.0.1 PowerDNS PowerDNS 3.0 PowerDNS PowerDNS 3.1 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
PowerDNS PowerDNS 3.1.7 .2 |
Discussion
PowerDNS Recursor Remote Cache Poisoning Vulnerability
PowerDNS is prone to a remote cache-poisoning vulnerability.
An attacker can exploit this issue to divert data from a legitimate site to an attacker-specified site.
Successful exploits will allow the attacker to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
PowerDNS 3.1.7.1 and earlier are vulnerable.
PowerDNS is prone to a remote cache-poisoning vulnerability.
An attacker can exploit this issue to divert data from a legitimate site to an attacker-specified site.
Successful exploits will allow the attacker to manipulate cache data, potentially facilitating man-in-the-middle, site-impersonation, or denial-of-service attacks.
PowerDNS 3.1.7.1 and earlier are vulnerable.
Exploit / POC
PowerDNS Recursor Remote Cache Poisoning Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PowerDNS Recursor Remote Cache Poisoning Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
Debian Linux 4.0 powerpc
Debian Linux 5.0 alpha
PowerDNS PowerDNS 3.1
Debian Linux 5.0 ia-32
Debian Linux 5.0 s/390
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 s/390
Debian Linux 4.0 alpha
Debian Linux 5.0 amd64
Debian Linux 5.0 powerpc
Debian Linux 4.0 ia-64
PowerDNS PowerDNS 3.0
PowerDNS PowerDNS 3.0.1
PowerDNS PowerDNS 3.1.1
PowerDNS PowerDNS 3.1.2
PowerDNS PowerDNS 3.1.3
PowerDNS PowerDNS 3.1.4
PowerDNS PowerDNS 3.1.5
PowerDNS PowerDNS 3.1.6
PowerDNS PowerDNS 3.1.7 .1
PowerDNS PowerDNS 3.1.7
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
-
Debian pdns-recursor_3.1.7-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_ia64.deb
Debian Linux 4.0 powerpc
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_powerpc.deb
Debian Linux 5.0 alpha
-
Debian pdns-recursor_3.1.7-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_alpha.deb
PowerDNS PowerDNS 3.1
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
Debian Linux 5.0 ia-32
-
Debian pdns-recursor_3.1.7-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_i386.deb
Debian Linux 5.0 s/390
-
Debian pdns-recursor_3.1.7-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_s390.deb
Debian Linux 4.0 amd64
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_i386.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_i386.deb
Debian Linux 4.0 s/390
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_s390.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_s390.deb
Debian Linux 4.0 alpha
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_alpha.deb
Debian Linux 5.0 amd64
-
Debian pdns-recursor_3.1.7-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_amd64.deb
Debian Linux 5.0 powerpc
-
Debian pdns-recursor_3.1.7-1+lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.7-1+lenny1_powerpc.deb
Debian Linux 4.0 ia-64
-
Debian pdns-recursor_3.1.4+v3.1.7-0+etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/pdns-recursor/pdns-recu rsor_3.1.4+v3.1.7-0+etch1_ia64.deb
PowerDNS PowerDNS 3.0
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.0.1
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.1
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.2
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.3
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.4
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.5
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.6
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.7 .1
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
PowerDNS PowerDNS 3.1.7
-
PowerDNS pdns-recursor-3.1.7.2.tar.bz2
http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.2.tar.bz2
References
PowerDNS Recursor Remote Cache Poisoning Vulnerability
References:
References:
- PowerDNS Homepage (PowerDNS)
- PowerDNS Security Advisory 2010-02 (PowerDNS)
- Critical PowerDNS Recursor Security Vulnerabilities: please upgrade ASAP to 3.1. (bert hubert
)