Denial of service in PowerDNS - CVE-2016-5427

 

Denial of service in PowerDNS - CVE-2016-5427

Published: September 13, 2016


Vulnerability identifier: #VU412
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5427
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause excessive resources spending on the target system.
The weakness exists due to sending of specially crafted DNS queries with label values containing a dot character ('.') that may lead to denial of service.
The vulnerability may result in consuming of excessive resources and denial of service on the vulnerable system.


Affected software

PowerDNS
Arch Linux
Debian Linux
Fedora
pdns

How to mitigate CVE-2016-5427

Update to 3.4.10.

pdns - addressed in versions 3.3.3-2.el6, 3.4.10-1.el7, 3.4.10-1.fc23

External References

Related Security Bulletins