Improper input validation in PowerDNS - CVE-2016-6172
Published: July 8, 2016 / Updated: November 22, 2018
Vulnerability identifier: #VU102
CSH Severity: High
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6172
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause the target service to crash.
The vulnerability exists due to resource error in PowerDNS. A remote unauthenticated attacker can cause the target service to crash by sending a specially crafted AXFR response or IXFR response.
Successful exploitation of this vulnerability may result in denial of service via network
The vulnerability exists due to resource error in PowerDNS. A remote unauthenticated attacker can cause the target service to crash by sending a specially crafted AXFR response or IXFR response.
Successful exploitation of this vulnerability may result in denial of service via network
Affected software
PowerDNS
Debian Linux
Fedora
pdns
Debian Linux
Fedora
pdns
How to mitigate CVE-2016-6172
Cybersecurity Help is currently unaware of any official solution, which resolves this vulnerability.
An unofficial, third-party patch is available at: https://github.com/sischkg/xfer-limit.
An unofficial, third-party patch is available at: https://github.com/sischkg/xfer-limit.
pdns - addressed in versions 3.3.3-2.el6, 4.0.1-1.fc24