CVE-2008-4194
Estado: ModificadaMedia (5)—
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.93%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-399
Referencias
- http://www.phys.uu.nl/~rombouts/pdnsd.html
- http://www.phys.uu.nl/~rombouts/pdnsd/ChangeLog
- http://www.vupen.com/english/advisories/2008/2582
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45594
- http://www.phys.uu.nl/~rombouts/pdnsd.html
- http://www.phys.uu.nl/~rombouts/pdnsd/ChangeLog
- http://www.vupen.com/english/advisories/2008/2582
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45594
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4194",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-09-24T11:42:25.327",
"references": [
{
"url": "http://www.phys.uu.nl/~rombouts/pdnsd.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.phys.uu.nl/~rombouts/pdnsd/ChangeLog",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2582",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45594",
"source": "cve@mitre.org"
},
{
"url": "http://www.phys.uu.nl/~rombouts/pdnsd.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.phys.uu.nl/~rombouts/pdnsd/ChangeLog",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2582",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45594",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a \"dangling pointer bug.\""
},
{
"lang": "es",
"value": "La función p_exec_query en src/dns_query.c de pdnsd antes de 1.2.7-par permite a atacantes remotos provocar una denegación de servicio (caída del demonio) mediante una respuesta DNS con muchas entradas en la sección de respuesta, relacionado con un \"dangling pointer bug (error de puntero colgado)\"."
}
],
"lastModified": "2026-06-16T22:57:21.250",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48C89DEE-EA5F-4A74-8D84-9632633DC9D8",
"versionEndIncluding": "1.2.6-par"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72E5E5EA-123B-4187-BAC0-77B3034BB665"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.7a:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1848A537-D8B7-4C56-980B-B19237603A21"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.8b1-par4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AA9D9AA-7FD4-4640-8A05-F353F193F624"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.8b1-par5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55C8B60D-9ABF-44EA-8C5F-737F12790C39"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.8b1-par6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "958FDA46-C58C-440E-B164-A88681CCDE50"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.8b1-par7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A591F5A-9C82-4125-9F3E-F8FB22F84A74"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.8b1-par8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A48F1CAE-0A43-43AD-8945-2EDDAE3A3E97"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.9-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8587AC06-C4F3-4078-A661-602BA9E568B6"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.10-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4DAA355-14BE-4462-B1D0-A2D4B5642ECF"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.11-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE0CC736-279C-4215-98CE-4904A35B4C4E"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.1.11a-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "176CCFD5-9AE7-43B2-9DE5-EA09C22465E6"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.2-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA858757-834E-45E1-BB1A-E9A9E377C6FF"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.2.1_par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF7A894A-4CE6-415E-8601-F495D8DBEE0F"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.2.4-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FEE1472-7A5B-4344-8B95-EC898D55419E"
},
{
"criteria": "cpe:2.3:a:pdnsd:pdnsd:1.2.5-par:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "853163E2-965E-4E35-9DD1-05710F1CAF3B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}