CVE-2015-5311
published 2015-11-17CVE-2015-5311: PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via…
PriorityP339medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
67.46%
99.2th percentile
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns 3.4.7-1 (bookworm) | pdns 3.4.7-1 (bookworm) |
| debian | pdns-recursor | < pdns 3.4.7-1 (bookworm) | pdns 3.4.7-1 (bookworm) |
| open-xchange | pdns | >= 0 < 3.4.7-1 | 3.4.7-1 |
| open-xchange | pdns | >= 0 < 3.4.7-1 | 3.4.7-1 |
| open-xchange | pdns | >= 0 < 3.4.7-1 | 3.4.7-1 |
| open-xchange | pdns | >= 0 < 3.4.7-1 | 3.4.7-1 |
| powerdns | authoritative | — | — |
| powerdns | authoritative | — | — |
| powerdns | authoritative | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target service is PowerDNS Authoritative Server (pdns_server process); a crash/assertion failure of the pdns_server process indicates exploitation of this DoS vulnerability via crafted query packets. ↗
- →Only PowerDNS Authoritative Server versions 3.4.4 through 3.4.6 are vulnerable; the PowerDNS Recursor is NOT affected. Scope exploitation attempts to DNS query traffic directed at pdns Authoritative Server instances in this version range. ↗
- →The vulnerability was discovered via afl-fuzz in the packet parsing code; monitor for repeated unexpected crashes/restarts of pdns_server, especially when run under a supervisor (guardian/systemd/supervisord), as rapid restart cycles may indicate active exploitation. ↗
- →Upstream patches for this issue are available at the PowerDNS patches download location; reference for patch diffing or signature extraction. ↗
- ·When pdns_server is run inside the guardian (--guardian) or a supervisor like supervisord or systemd, it will automatically restart after a crash, limiting observable impact to degraded service rather than a full outage. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-5311: pdns - PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attack...
vendor_debian·2015·CVSS 5.0
CVE-2015-5311 [MEDIUM] CVE-2015-5311: pdns - PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attack...
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
Scope: local
bookworm: resolved (fixed in 3.4.7-1)
bullseye: resolved (fixed in 3.4.7-1)
forky: resolved (fixed in 3.4.7-1)
sid: resolved (fixed in 3.4.7-1)
trixie: resolved (fixed in 3.4.7-1)
GHSA
GHSA-hcqm-j37x-5h8w: PowerDNS (aka pdns) Authoritative Server 3
ghsa_unreviewed·2022-05-17
CVE-2015-5311 [MEDIUM] CWE-20 GHSA-hcqm-j37x-5h8w: PowerDNS (aka pdns) Authoritative Server 3
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
OSV
CVE-2015-5311: PowerDNS (aka pdns) Authoritative Server 3
osv·2015-11-17·CVSS 5.0
CVE-2015-5311 [MEDIUM] CVE-2015-5311: PowerDNS (aka pdns) Authoritative Server 3
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS)
bugzilla·2015-11-09·CVSS 5.0
CVE-2015-5311 [MEDIUM] CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS)
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS)
The following flaw was found in PowerDNS Authoritative Server:
A bug was found using afl-fuzz in our packet parsing code. This bug, when exploited, this causes an assertion error and consequent termination of the the pdns_server process, causing a Denial of Service.
When the PowerDNS Authoritative Server is run inside the guardian (--guardian), or inside a supervisor like supervisord or systemd, it will be automatically restarted, limiting the impact to a somewhat degraded service.
PowerDNS Authoritative Server 3.4.4 - 3.4.6 are affected. No other versions are affected. The PowerDNS Recursor is not affected.
PowerDNS Authoritative Server 3.4.7 contains a fix to this issue.
Discussion:
Created pdns tracking bugs for thi
Bugzilla
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [epel-all]
bugzilla·2015-11-09·CVSS 5.0
CVE-2015-5311 [MEDIUM] CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [epel-all]
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [fedora-all]
bugzilla·2015-11-09·CVSS 5.0
CVE-2015-5311 [MEDIUM] CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [fedora-all]
CVE-2015-5311 pdns: packet parsing bug can lead to crashes (DoS) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171865.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171976.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172193.htmlhttp://www.openwall.com/lists/oss-security/2015/11/09/3http://www.securitytracker.com/id/1034098https://doc.powerdns.com/md/security/powerdns-advisory-2015-03/http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171865.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171976.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172193.htmlhttp://www.openwall.com/lists/oss-security/2015/11/09/3http://www.securitytracker.com/id/1034098https://doc.powerdns.com/md/security/powerdns-advisory-2015-03/
2015-11-17
Published