cbcvebase.
CVE-2016-6172
published 2016-09-26

CVE-2016-6172: PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS…

medium6.8CVSS 3.0
AVNACHPRNUINSCCNINAH
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianpdns< pdns 4.0.1-1 (bookworm)pdns 4.0.1-1 (bookworm)
open-xchangepdns>= 0 < 4.0.1-14.0.1-1
open-xchangepdns>= 0 < 4.0.1-14.0.1-1
open-xchangepdns>= 0 < 4.0.1-14.0.1-1
open-xchangepdns>= 0 < 4.0.1-14.0.1-1
opensuseleap
opensuseopensuse
powerdnsauthoritative_server<= 4.0.0

CVSS provenance

nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
osv6.8MEDIUM