CVE-2022-27227

NameCVE-2022-27227
DescriptionIn PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pdns (PTS)bullseye4.4.1-1vulnerable
bookworm4.7.3-2fixed
trixie4.9.7-1fixed
forky, sid5.0.3-1fixed
pdns-recursor (PTS)bullseye4.4.2-3vulnerable
bookworm, bookworm (security)4.8.8-1+deb12u1fixed
trixie (security), trixie5.2.8-0+deb13u1fixed
forky, sid5.4.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pdnssource(unstable)4.6.1-1
pdns-recursorsourcebullseye(unfixed)end-of-life
pdns-recursorsource(unstable)4.6.1-1

Notes

[bullseye] - pdns-recursor <end-of-life> (No longer supported with security updates in Bullseye)
[buster] - pdns-recursor <no-dsa> (Minor issue)
[stretch] - pdns-recursor <no-dsa> (Minor issue)
https://github.com/PowerDNS/pdns/commit/ff27c8c8e17bd8093e4668d88865b8eb71039b45 (rec-4.4.8)
[bullseye] - pdns <no-dsa> (Minor issue)
[buster] - pdns <no-dsa> (Minor issue)
[stretch] - pdns <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2022/03/25/1
https://github.com/PowerDNS/pdns/commit/57312d230d5c01d9aca58cb29ce87e23ccbbefd2 (auth-4.4.3)

Search for package or bug name: Reporting problems