The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
References
| Link | Resource |
|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html | Third Party Advisory |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html | Third Party Advisory |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html | Third Party Advisory |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html | Third Party Advisory |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html | Third Party Advisory |
| http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html | Third Party Advisory |
| http://www.securitytracker.com/id/1032220 | Third Party Advisory |
| http://www.securityfocus.com/bid/74306 | Third Party Advisory |
| http://www.debian.org/security/2015/dsa-3307 | |
| http://www.debian.org/security/2015/dsa-3306 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2015-05-18 15:59
Updated : 2016-12-28 02:59
NVD link : CVE-2015-1868
Mitre link : CVE-2015-1868
JSON object : View
Products Affected
fedoraproject
- fedora
powerdns
- authoritative
- recursor
CWE
CWE-399
Resource Management Errors
