CVE-2015-1868
high · 7.8The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
7.8
CVSS
81.7%
EPSS (exploit prob.)
100th
EPSS percentile
2015-05-18
Published
AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
CWE-399
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| powerdns | authoritative | 3.2 |
| powerdns | authoritative | 3.3 |
| powerdns | authoritative | 3.3.1 |
| powerdns | authoritative | 3.3.2 |
| powerdns | authoritative | 3.4.0 |
| powerdns | authoritative | 3.4.1 |
| powerdns | authoritative | 3.4.3 |
| fedoraproject | fedora | 20 |
| fedoraproject | fedora | 21 |
| fedoraproject | fedora | 22 |
| powerdns | recursor | 3.5 |
| powerdns | recursor | 3.5.1 |
| powerdns | recursor | 3.5.2 |
| powerdns | recursor | 3.5.3 |
| powerdns | recursor | 3.6.0 |
| powerdns | recursor | 3.6.1 |
| powerdns | recursor | 3.6.2 |
| powerdns | recursor | 3.6.3 |
| powerdns | recursor | 3.7.1 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html
- http://www.debian.org/security/2015/dsa-3306
- http://www.debian.org/security/2015/dsa-3307
- http://www.securityfocus.com/bid/74306
- http://www.securitytracker.com/id/1032220
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.html
- http://www.debian.org/security/2015/dsa-3306
- http://www.debian.org/security/2015/dsa-3307
- http://www.securityfocus.com/bid/74306
- http://www.securitytracker.com/id/1032220
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-1868