[oss-security] 20210726 security advisory 2021-01 for PowerDNS Authoritative Server 4.5.0mailing list
http://www.openwall.com/lists/oss-security/2021/07/26/2 CVE-2021-36754
HIGHNuclei
powerdns authoritative_server Improper Restriction of Operations within the Bounds of a Memory Buffer
Record summary
CVE-2021-36754 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 20, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
authoritative_serverBrowse powerdns / authoritative_server | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHPowerDNS Authoritative Server - Denial of ServiceCVSS 7.5
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
Impact
Attackers can crash the server process, leading to denial of service and potential service disruption.
Remediation
Upgrade to version 4.5.1 or later.
WeaknessesCWE-119
Authorsdaffainfo
Template tagscvecve2021jsdnspowerdnsauthoritative_serverdosintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:*
http://www.openwall.com/lists/oss-security/2021/07/26/2 https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html https://nvd.nist.gov/vuln/detail/CVE-2021-36754
Source: ProjectDiscovery
References
4doc.powerdns.com
https://doc.powerdns.com/authoritative/security-advisories/index.html doc.powerdns.comConfirmation
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-36754