Resource management error in PowerDNS Recursor and PowerDNS Authoritative - CVE-2015-1868

 

Resource management error in PowerDNS Recursor and PowerDNS Authoritative - CVE-2015-1868

Published: December 28, 2016 / Updated: June 21, 2025


Vulnerability identifier: #VU111724
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1868
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.


Affected software

PowerDNS Recursor
PowerDNS Authoritative
Fedora
pdns
pdns-recursor

How to mitigate CVE-2015-1868

Install update from vendor's website.

PowerDNS Recursor - addressed in versions 3.3.2, 3.4.4, 3.6.3, 3.7.2
PowerDNS Authoritative - addressed in versions 3.3.2, 3.4.4
pdns - addressed in versions 3.3.1-2.el6, 3.4.4-1.el7, 3.4.4-1.fc21, 3.4.4-1.fc22
pdns-recursor - addressed in versions 3.6.3-1.el5, 3.7.2-1.el6, 3.7.2-1.el7, 3.7.2-1.fc21, 3.7.2-1.fc22

External References

Related Security Bulletins