Vulnerability CVE-2016-6172


Published: 2016-09-26

Description:
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.1/10
6.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Powerdns -> Authoritative server 
Opensuse -> LEAP 
Opensuse -> Opensuse 
Novell -> LEAP 
Novell -> Opensuse 

 References:
http://lists.opensuse.org/opensuse-updates/2016-08/msg00085.html
http://www.debian.org/security/2016/dsa-3664
http://www.openwall.com/lists/oss-security/2016/07/06/3
http://www.securityfocus.com/bid/91678
http://www.securitytracker.com/id/1036242
https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-401
https://github.com/PowerDNS/pdns/issues/4128
https://github.com/PowerDNS/pdns/issues/4133
https://github.com/PowerDNS/pdns/pull/4134
https://github.com/sischkg/xfer-limit/blob/master/README.md
https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html

Copyright 2024, cxsecurity.com

 

Back to Top