PT-2014-8646 · Powerdns · Powerdns Recursor
Florian Maury
·
Published
2014-12-10
·
Updated
2024-06-15
·
CVE-2014-8601
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
PowerDNS Recursor versions prior to 3.6.2
Description
The issue allows remote attackers to cause performance degradations via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it. This is due to the lack of limitation on delegation chaining.
Recommendations
For PowerDNS Recursor versions prior to 3.6.2, update to version 3.6.2 or later to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerdns Recursor