cbcvebase.
CVE-2015-5311
published 2015-11-17

CVE-2015-5311: PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via…

PriorityP339medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
67.46%
99.2th percentile
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 3.4.7-1 (bookworm)pdns 3.4.7-1 (bookworm)
debianpdns-recursor< pdns 3.4.7-1 (bookworm)pdns 3.4.7-1 (bookworm)
open-xchangepdns>= 0 < 3.4.7-13.4.7-1
open-xchangepdns>= 0 < 3.4.7-13.4.7-1
open-xchangepdns>= 0 < 3.4.7-13.4.7-1
open-xchangepdns>= 0 < 3.4.7-13.4.7-1
powerdnsauthoritative
powerdnsauthoritative
powerdnsauthoritative

Detection & IOCsextracted from sources · hover to see the quote

  • Target service is PowerDNS Authoritative Server (pdns_server process); a crash/assertion failure of the pdns_server process indicates exploitation of this DoS vulnerability via crafted query packets.
  • Only PowerDNS Authoritative Server versions 3.4.4 through 3.4.6 are vulnerable; the PowerDNS Recursor is NOT affected. Scope exploitation attempts to DNS query traffic directed at pdns Authoritative Server instances in this version range.
  • The vulnerability was discovered via afl-fuzz in the packet parsing code; monitor for repeated unexpected crashes/restarts of pdns_server, especially when run under a supervisor (guardian/systemd/supervisord), as rapid restart cycles may indicate active exploitation.
  • Upstream patches for this issue are available at the PowerDNS patches download location; reference for patch diffing or signature extraction.
  • ·When pdns_server is run inside the guardian (--guardian) or a supervisor like supervisord or systemd, it will automatically restart after a crash, limiting observable impact to degraded service rather than a full outage.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.