CVE-2015-1868

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
powerdnsauthoritative
3.2
powerdnsauthoritative
3.3
powerdnsauthoritative
3.3.1
powerdnsauthoritative
3.3.2
powerdnsauthoritative
3.4.0
powerdnsauthoritative
3.4.1
powerdnsauthoritative
3.4.3
powerdnsrecursor
3.5
powerdnsrecursor
3.5.1
powerdnsrecursor
3.5.2
powerdnsrecursor
3.5.3
powerdnsrecursor
3.6.0
powerdnsrecursor
3.6.1
powerdnsrecursor
3.6.2
powerdnsrecursor
3.6.3
powerdnsrecursor
3.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pdns
bullseye
4.4.1-1
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
4.7.3-2
fixed
sid
4.9.2-1
fixed
trixie
4.9.2-1
fixed
pdns-recursor
bullseye
4.4.2-3
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
4.8.8-1
fixed
bookworm (security)
4.8.8-1
fixed
sid
5.0.9-1
fixed
trixie
5.0.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pdns
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
ignored
utopic
ignored
trusty
Fixed 3.3-2ubuntu0.1
released
precise
not-affected
lucid
ignored
pdns-recursor
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
Fixed 3.6.2-2+deb8u2build0.15.04.1
released
utopic
ignored
trusty
Fixed 3.5.3-1ubuntu0.1
released
precise
not-affected
lucid
ignored
Common Weakness Enumeration