Search CVE reports
1 – 10 of 57 results
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
1 affected package
nsd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nsd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were...
1 affected package
nsd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nsd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(Any remote client can crash a (debugging/non-release build type) NSD s ...)
1 affected package
nsd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nsd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(Any remote client can crash a NSD serve child, by throttling the TCP r ...)
1 affected package
nsd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nsd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
[A crafted DNS packet can cause increased memory and CPU consumption]
3 affected packages
dnsdist, pdns, pdns-recursor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dnsdist | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| pdns | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| pdns-recursor | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling....
2 affected packages
h2o, dnsdist
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| h2o | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| dnsdist | Not affected | Needs evaluation | Not affected | Not affected | Not affected |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the...
2 affected packages
h2o, dnsdist
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| h2o | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| dnsdist | Not affected | Needs evaluation | Not affected | Not affected | Not affected |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over...
2 affected packages
h2o, dnsdist
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| h2o | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| dnsdist | Not affected | Needs evaluation | Not affected | Not affected | Not affected |
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate...
2 affected packages
h2o, dnsdist
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| h2o | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| dnsdist | Not affected | Needs evaluation | Not affected | Not affected | Not affected |
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that...
1 affected package
dnsdist
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dnsdist | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |