CVE-2015-1868

EUVD-2015-1974
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
powerdnsauthoritative
3.2
powerdnsauthoritative
3.3
powerdnsauthoritative
3.3.1
powerdnsauthoritative
3.3.2
powerdnsauthoritative
3.4.0
powerdnsauthoritative
3.4.1
powerdnsauthoritative
3.4.3
powerdnsrecursor
3.5
powerdnsrecursor
3.5.1
powerdnsrecursor
3.5.2
powerdnsrecursor
3.5.3
powerdnsrecursor
3.6.0
powerdnsrecursor
3.6.1
powerdnsrecursor
3.6.2
powerdnsrecursor
3.6.3
powerdnsrecursor
3.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pdns
bookworm
4.7.3-2
fixed
bullseye
4.4.1-1
fixed
sid
4.9.2-1
fixed
squeeze
not-affected
trixie
4.9.2-1
fixed
wheezy
not-affected
pdns-recursor
bookworm
4.8.8-1
fixed
bookworm (security)
4.8.8-1
fixed
bullseye
4.4.2-3
fixed
sid
5.0.9-1
fixed
squeeze
not-affected
trixie
5.0.9-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pdns
lucid
ignored
precise
not-affected
trusty
Fixed 3.3-2ubuntu0.1
released
utopic
ignored
vivid
ignored
wily
not-affected
xenial
not-affected
yakkety
not-affected
pdns-recursor
lucid
ignored
precise
not-affected
trusty
Fixed 3.5.3-1ubuntu0.1
released
utopic
ignored
vivid
Fixed 3.6.2-2+deb8u2build0.15.04.1
released
wily
not-affected
xenial
not-affected
yakkety
not-affected
Common Weakness Enumeration