Vulnerability Details CVE-2018-14644
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2018-14644
-
cpe:2.3:a:powerdns:recursor:4.0.0
-
cpe:2.3:a:powerdns:recursor:4.0.1
-
cpe:2.3:a:powerdns:recursor:4.0.2
-
cpe:2.3:a:powerdns:recursor:4.0.3
-
cpe:2.3:a:powerdns:recursor:4.0.4
-
cpe:2.3:a:powerdns:recursor:4.0.5
-
cpe:2.3:a:powerdns:recursor:4.0.6
-
cpe:2.3:a:powerdns:recursor:4.0.7
-
cpe:2.3:a:powerdns:recursor:4.0.8
-
cpe:2.3:a:powerdns:recursor:4.1.0
-
cpe:2.3:a:powerdns:recursor:4.1.1
-
cpe:2.3:a:powerdns:recursor:4.1.2
-
cpe:2.3:a:powerdns:recursor:4.1.3
-
cpe:2.3:a:powerdns:recursor:4.1.4