UBUNTU-CVE-2022-27227
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-27227
UBUNTU-CVE-2022-27227
Summary:
Details: In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
References: https://ubuntu.com/security/CVE-2022-27227, https://www.openwall.com/lists/oss-security/2022/03/25/1, https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-01.html, https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2022-01.html, https://docs.powerdns.com/recursor/security-advisories/index.html, https://doc.powerdns.com/authoritative/security-advisories/index.html, http://www.openwall.com/lists/oss-security/2022/03/25/1, https://www.cve.org/CVERecord?id=CVE-2022-27227, https://ubuntu.com/security/notices/USN-7203-1
Affected packages
Package
Name: pdns
Purl: pkg:deb/ubuntu/[email protected]~alpha2-3ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
