CVE-2015-5470
Published Nov 2, 2015
Last updated 9 years ago
Overview
- Description
- The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- CWE-399
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF978920-5AEA-4B22-9ACC-E8CFD9BCC121", "versionEndIncluding": "3.3.2" }, { "criteria": "cpe:2.3:a:powerdns:authoritative:3.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04A975C2-F387-4815-BDD7-F712AFFE1CE3" }, { "criteria": "cpe:2.3:a:powerdns:authoritative:3.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91211D89-B43C-4D26-8ADE-90EEAFA44603" }, { "criteria": "cpe:2.3:a:powerdns:authoritative:3.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3F120B2-C520-406E-A6A7-7E710D434FE4" }, { "criteria": "cpe:2.3:a:powerdns:authoritative:3.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CA372BE-95F8-48BA-A1AF-D9FEDF01AC18" }, { "criteria": "cpe:2.3:a:powerdns:authoritative:3.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1700CF93-6C36-4395-92C4-708B4CE9861D" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD93A3D6-4421-493B-863A-83983289DD0F", "versionEndIncluding": "3.6.3" }, { "criteria": "cpe:2.3:a:powerdns:recursor:3.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79723D52-8A9E-42B5-AF68-4DBF4758783E" }, { "criteria": "cpe:2.3:a:powerdns:recursor:3.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "258E1BC4-F4A8-4A2A-9766-F6BB10C982C7" } ], "operator": "OR" } ] } ]