FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

PowerDNS -- LDAP backend fails to escape all queries

Affected packages
powerdns < 2.9.18

Details

VuXML ID 43a7b0a7-f9bc-11d9-b473-00061bc2ad93
Discovery 2005-07-16
Entry 2005-07-21

The LDAP backend in PowerDNS has issues with escaping queries which could cause connection errors. This would make it possible for a malicious user to temporarily blank domains.

This is known to affect all releases prior to 2.9.18.

References

CVE Name CVE-2005-2302
URL http://doc.powerdns.com/security-policy.html
URL http://marc.theaimsgroup.com/?l=bugtraq&m=112155941310297&w=2