CVE-2015-1868

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
18/05/2015
Last modified:
12/04/2025

Description

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:powerdns:authoritative:3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.3:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.0:*:*:*:*:*:*:*