Improper input validation in PowerDNS - CVE-2016-6172

 

Improper input validation in PowerDNS - CVE-2016-6172

Published: July 8, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU102
CSH Severity: High
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6172
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the target service to crash.

The vulnerability exists due to resource error in PowerDNS. A remote unauthenticated attacker can cause the target service to crash by sending a specially crafted AXFR response or IXFR response.

Successful exploitation of this vulnerability may result in denial of service via network

Affected software

PowerDNS
Debian Linux
Fedora
pdns

How to mitigate CVE-2016-6172

Cybersecurity Help is currently unaware of any official solution, which resolves this vulnerability.

 An unofficial, third-party patch is available at: https://github.com/sischkg/xfer-limit.

pdns - addressed in versions 3.3.3-2.el6, 4.0.1-1.fc24

External References

Related Security Bulletins