PT-2016-6782 · Suse+1 · Opensuse Leap+2

Rgacogne

·

Published

2016-09-10

·

Updated

2024-06-15

·

CVE-2016-6172

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PowerDNS (aka pdns) Authoritative Server versions prior to 4.0.1 opensuse (affected versions not specified) opensuse leap (affected versions not specified) PowerDNS Authoritative Server (affected versions not specified)
Description The issue allows remote primary DNS servers to cause a denial of service, resulting in memory exhaustion and secondary DNS server crash. This can be achieved via a large AXFR or IXFR response.
Recommendations For PowerDNS (aka pdns) Authoritative Server versions prior to 4.0.1, update to version 4.0.1 or later to resolve the issue. For opensuse and opensuse leap, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting large AXFR or IXFR responses from remote primary DNS servers to minimize the risk of exploitation.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6172
DLA-627-1
DSA-3664-1
MGASA-2016-0324
OPENSUSE-SU-2024:10136-1
OPENSUSE-SU-2024:10537-1

Affected Products

Powerdns Authoritative Server
Opensuse
Opensuse Leap