PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service (performance degradations) via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 7.0 (including) | 7.0 (including) |
Pdns-recursor | Ubuntu | lucid | * |
Pdns-recursor | Ubuntu | precise | * |
Pdns-recursor | Ubuntu | trusty | * |
Pdns-recursor | Ubuntu | upstream | * |
Pdns-recursor | Ubuntu | utopic | * |