Candidate: CVE-2020-17482 PublicDate: 2020-10-02 09:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17482 https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-05.html Description: An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=970737 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N [4.3 MEDIUM] Patches_pdns: upstream_pdns: released (4.3.1-1) precise/esm_pdns: DNE trusty_pdns: ignored (out of standard support) trusty/esm_pdns: DNE xenial_pdns: ignored (end of standard support, was needs-triage) bionic_pdns: needs-triage focal_pdns: needs-triage groovy_pdns: ignored (reached end-of-life) hirsute_pdns: not-affected (4.3.1-1) impish_pdns: not-affected (4.3.1-1) jammy_pdns: not-affected (4.3.1-1) devel_pdns: not-affected (4.3.1-1)