CVE-2015-1868

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:powerdns:authoritative:3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:powerdns:recursor:3.5:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.7.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-05-18 15:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-1868

Mitre link : CVE-2015-1868

CVE.ORG link : CVE-2015-1868


JSON object : View

Products Affected

powerdns

  • authoritative
  • recursor

fedoraproject

  • fedora
CWE
CWE-399

Resource Management Errors