CVE-2015-5470

The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
powerdnsauthoritative
𝑥
≤ 3.3.2
powerdnsauthoritative
3.4.0
powerdnsauthoritative
3.4.1
powerdnsauthoritative
3.4.2
powerdnsauthoritative
3.4.3
powerdnsauthoritative
3.4.4
powerdnsrecursor
𝑥
≤ 3.6.3
powerdnsrecursor
3.7.1
powerdnsrecursor
3.7.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pdns
bullseye
4.4.1-1
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
4.7.3-2
fixed
sid
4.9.2-1
fixed
trixie
4.9.2-1
fixed
pdns-recursor
bullseye
4.4.2-3
fixed
wheezy
not-affected
squeeze
not-affected
bookworm
4.8.8-1
fixed
bookworm (security)
4.8.8-1
fixed
sid
5.0.9-1
fixed
trixie
5.0.9-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pdns
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
ignored
utopic
ignored
trusty
dne
precise
not-affected
pdns-recursor
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
Fixed 3.6.2-2+deb8u2build0.15.04.1
released
utopic
ignored
trusty
Fixed 3.5.3-1ubuntu0.1
released
precise
not-affected
Common Weakness Enumeration