Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PowerDNS LDAP query 拒绝服务漏洞
Vulnerability Description
PowerDNS是荷兰PowerDNS公司的一个跨平台的开源DNS服务组件,它支持在Windows系统中使用Access的mdb文件记录DNS信息,在Linux/Unix系统中使用MySQL来记录DNS信息。 PowerDNS 2.9.18之前的版本存在拒绝服务漏洞。 在运行于LDAP后端时,由于未正确避开LDAP查询,远程攻击者可以使系统拒绝服务(回答ldap问题失败),并可能执行LDAP注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A