CVE-2015-1868
Summary
| CVE | CVE-2015-1868 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-18 15:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 20 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Operating System | Fedoraproject | Fedora | 22 | All | All | All |
| Application | Powerdns | Authoritative | 3.2 | All | All | All |
| Application | Powerdns | Authoritative | 3.3 | All | All | All |
| Application | Powerdns | Authoritative | 3.3.1 | All | All | All |
| Application | Powerdns | Authoritative | 3.3.2 | All | All | All |
| Application | Powerdns | Authoritative | 3.4.0 | All | All | All |
| Application | Powerdns | Authoritative | 3.4.1 | All | All | All |
| Application | Powerdns | Authoritative | 3.4.3 | All | All | All |
| Application | Powerdns | Recursor | 3.5 | All | All | All |
| Application | Powerdns | Recursor | 3.5.1 | All | All | All |
| Application | Powerdns | Recursor | 3.5.2 | All | All | All |
| Application | Powerdns | Recursor | 3.5.3 | All | All | All |
| Application | Powerdns | Recursor | 3.6.0 | All | All | All |
| Application | Powerdns | Recursor | 3.6.1 | All | All | All |
| Application | Powerdns | Recursor | 3.6.2 | All | All | All |
| Application | Powerdns | Recursor | 3.6.3 | All | All | All |
| Application | Powerdns | Recursor | 3.7.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3306-1 pdns | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 22 Update: pdns-3.4.4-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 20 Update: pdns-3.3.1-3.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 20 Update: pdns-recursor-3.7.2-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Multiple PowerDNS Products CVE-2015-1868 Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory |
| Debian -- Security Information -- DSA-3307-1 pdns-recursor | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 22 Update: pdns-recursor-3.7.2-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| PowerDNS Label Decompression Bug Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory |
| [SECURITY] Fedora 21 Update: pdns-3.4.4-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 21 Update: pdns-recursor-3.7.2-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.