cbcvebase.
CVE-2016-5427
published 2016-09-21

CVE-2016-5427: PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of…

PriorityP353high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
62.98%
99.1th percentile
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 4.0.0~alpha1-1 (bookworm)pdns 4.0.0~alpha1-1 (bookworm)
open-xchangepdns>= 0 < 4.0.0~alpha1-14.0.0~alpha1-1
open-xchangepdns>= 0 < 4.0.0~alpha1-14.0.0~alpha1-1
open-xchangepdns>= 0 < 4.0.0~alpha1-14.0.0~alpha1-1
open-xchangepdns>= 0 < 4.0.0~alpha1-14.0.0~alpha1-1
powerdnsauthoritative<= 3.4.9

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/PowerDNS/pdns/commit/881b5b03a590198d03008e4200dd00cc537712f3
  • Detect DNS queries where a label within the qname contains a literal dot (.) character — this is the crafted input vector for CVE-2016-5427 against PowerDNS Authoritative Server <= 3.4.9.
  • Monitor backend (e.g. SQL) CPU/load for abnormal spikes triggered by inbound DNS queries, which may indicate exploitation of this DoS vector.
  • The PowerDNS Recursor is NOT affected; focus detection and patching efforts solely on the Authoritative Server component running versions up to and including 3.4.9.
  • ·Only PowerDNS Authoritative Server versions up to and including 3.4.9 are vulnerable; version 3.4.10 and later (including 4.0.0+) contain the fix.
  • ·The attack is unauthenticated and remote — no credentials or prior access are required to send the crafted DNS query.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.