Lucene search

K
archlinuxArch LinuxASA-201609-9
HistorySep 13, 2016 - 12:00 a.m.

powerdns: denial of service

2016-09-1300:00:00
Arch Linux
lists.archlinux.org
11

0.797 High

EPSS

Percentile

98.3%

Two issues have been found in PowerDNS Authoritative Server allowing a
remote, unauthenticated attacker to cause an abnormal load on the
PowerDNS backend by sending crafted DNS queries, which might result in a
partial denial of service if the backend becomes overloaded. SQL
backends for example are particularly vulnerable to this kind of
unexpected load if they have not been dimensioned for it.

  • CVE-2016-5426

PowerDNS Authoritative Server accepts queries with a qname’s length
larger than 255 bytes.

  • CVE-2016-5427

PowerDNS Authoritative Server does not properly handle dot inside labels.

OSVersionArchitecturePackageVersionFilename
anyanyanypowerdns< 4.0.1-3UNKNOWN