CVE-2009-4009
CVE-2009-4009 is a critical-severity vulnerability in Powerdns Recursor with a CVSS 2.0 base score of 10.0. Its EPSS exploit-prediction score of 18% places it in the 97th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Critical (CVSS 2.0 base score 10.0)
- EPSS exploit prediction: 18% (97th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Powerdns Recursor
- Published:
- Last modified:
Description
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.
Frequently asked questions
- What is CVE-2009-4009?
- Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.
- How severe is CVE-2009-4009?
- CVE-2009-4009 has a CVSS 2.0 base score of 10.0, rated critical severity.
- Is CVE-2009-4009 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 18% (97th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2009-4009?
- CVE-2009-4009 primarily affects Powerdns Recursor. In total, 18 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2009-4009?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2009-4009 published?
- CVE-2009-4009 was published on 2010-01-08 and last updated on 2026-06-16.
References
- http://doc.powerdns.com/powerdns-advisory-2010-01.html
- http://secunia.com/advisories/38004
- http://secunia.com/advisories/38068
- http://securitytracker.com/id?1023403
- http://www.securityfocus.com/archive/1/508743/100/0/threaded
- http://www.securityfocus.com/bid/37650
- http://www.vupen.com/english/advisories/2010/0054
- https://bugzilla.redhat.com/show_bug.cgi?id=552285
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55438
- https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00217.html
- https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00228.html
Affected products (18)
- cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.0_rc1:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.8:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.9.15:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.9.16:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.9.17:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:2.9.18:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:powerdns:recursor:3.1.7.1:*:*:*:*:*:*:*
More vulnerabilities in Powerdns Recursor
- CVE-2020-10030 — High (CVSS 8.8): An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough…
- CVE-2025-59023 — High (CVSS 8.2): Crafted delegations or IP fragments can poison cached delegations in Recursor.
- CVE-2019-3806 — High (CVSS 8.1): An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied…
- CVE-2015-5470 — High (CVSS 7.8): The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth)…
- CVE-2015-1868 — High (CVSS 7.8): The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and…
- CVE-2025-59030 — High (CVSS 7.5): An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
All CVEs affecting Powerdns Recursor →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-105285 — Critical (CVSS 10.0): A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function…
- CVE-2026-104610 — Critical (CVSS 10.0): A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function…
- CVE-2026-101039 — Critical (CVSS 10.0): A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element…
- CVE-2026-96257 — Critical (CVSS 10.0): A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element…
- CVE-2026-94089 — Critical (CVSS 10.0): A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file…
- CVE-2026-94003 — Critical (CVSS 10.0): A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file…