CVE-2015-1868

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html Third Party Advisory
http://www.debian.org/security/2015/dsa-3306
http://www.debian.org/security/2015/dsa-3307
http://www.securityfocus.com/bid/74306 Third Party Advisory
http://www.securitytracker.com/id/1032220 Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html Third Party Advisory
http://www.debian.org/security/2015/dsa-3306
http://www.debian.org/security/2015/dsa-3307
http://www.securityfocus.com/bid/74306 Third Party Advisory
http://www.securitytracker.com/id/1032220 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:powerdns:authoritative:3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:3.4.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:powerdns:recursor:3.5:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:recursor:3.7.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-05-18 15:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-1868

Mitre link : CVE-2015-1868

CVE.ORG link : CVE-2015-1868


JSON object : View

Products Affected

powerdns

  • recursor
  • authoritative

fedoraproject

  • fedora
CWE
CWE-399

Resource Management Errors