Back to search
CVE-2005-2301
Published: Jul 19, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18
x_refsource_CONFIRM
SUSE-SR:2005:019
vendor-advisory
x_refsource_SUSE
20050716 PowerDNS 2.9.18 fixes two security issues affecting users of LDAP
mailing-list
x_refsource_BUGTRAQ
1014504
vdb-entry
x_refsource_SECTRACK
14290
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now