The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html - Third Party Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html - Third Party Advisory | |
References | () http://www.debian.org/security/2015/dsa-3306 - | |
References | () http://www.debian.org/security/2015/dsa-3307 - | |
References | () http://www.securityfocus.com/bid/74306 - Third Party Advisory | |
References | () http://www.securitytracker.com/id/1032220 - Third Party Advisory |
Information
Published : 2015-05-18 15:59
Updated : 2024-11-21 02:26
NVD link : CVE-2015-1868
Mitre link : CVE-2015-1868
CVE.ORG link : CVE-2015-1868
JSON object : View
Products Affected
powerdns
- authoritative
- recursor
fedoraproject
- fedora
CWE
CWE-399
Resource Management Errors