CVE-2014-8601: Medium severity debian linux vulnerability

Published Dec 10, 2014
·
Updated

PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.

Affected Software

2 affected components
Debian Debian Linux=7.0
PowerDNS recursor<=3.6.1

Event History

Dec 10, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2014-8601?

CVE-2014-8601 is classified as a high severity vulnerability due to its potential to cause denial of service by degrading performance.

2

How do I fix CVE-2014-8601?

To fix CVE-2014-8601, upgrade PowerDNS Recursor to version 3.6.2 or later.

3

What type of attack does CVE-2014-8601 allow?

CVE-2014-8601 allows remote attackers to cause performance degradation through excessive delegation chaining.

4

Which versions of PowerDNS are affected by CVE-2014-8601?

CVE-2014-8601 affects all versions of PowerDNS Recursor prior to 3.6.2.

5

What systems are vulnerable to CVE-2014-8601?

Systems running Debian Linux 7.0 and PowerDNS Recursor versions up to and including 3.6.1 are vulnerable to CVE-2014-8601.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203