Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Transfer requests received over DoH can lead to a denial of service in DNSdist
Vulnerability Description
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
PowerDNS DNSdist 安全漏洞
Vulnerability Description
PowerDNS DNSDist是荷兰PowerDNS公司的一款负载均衡器。该产品能够将流量分流到不同服务器,为用户提供最佳性能。 PowerDNS DNSdist 1.9.4之前版本存在安全漏洞,该漏洞源于攻击者可以通过发送区域传输请求来触发断言失败,从而导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A