CVE-2019-3806


01/29/2019

CVE-2019-3806

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

Attack vector: 
Network

Product: 
powerdns: recursor

References: 

Severity: 
Medium

CVSS Score: 
6.8

CVSS Vector: 
(AV:N/AC:M/Au:N/C:P/I:P/A:P)



Don't forget to share

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *