CVE Vulnerabilities

CVE-2015-1868

Published: May 18, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.

Affected Software

NameVendorStart VersionEnd Version
AuthoritativePowerdns3.2 (including)3.2 (including)
AuthoritativePowerdns3.3 (including)3.3 (including)
AuthoritativePowerdns3.3.1 (including)3.3.1 (including)
AuthoritativePowerdns3.3.2 (including)3.3.2 (including)
AuthoritativePowerdns3.4.0 (including)3.4.0 (including)
AuthoritativePowerdns3.4.1 (including)3.4.1 (including)
AuthoritativePowerdns3.4.3 (including)3.4.3 (including)
PdnsUbuntulucid*
PdnsUbuntutrusty*
PdnsUbuntuupstream*
PdnsUbuntuutopic*
PdnsUbuntuvivid*
Pdns-recursorUbuntulucid*
Pdns-recursorUbuntutrusty*
Pdns-recursorUbuntuupstream*
Pdns-recursorUbuntuutopic*
Pdns-recursorUbuntuvivid*

References