CVE-2015-5311: Input Validation
Published Nov 17, 2015
·Updated
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
Affected Software
3 affected components
PowerDNS=3.4.4
PowerDNS=3.4.5
PowerDNS=3.4.6
Remediation
Event History
Nov 17, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5311?
CVE-2015-5311 has been classified as high severity due to its ability to cause denial of service and crash the server.
2
How do I fix CVE-2015-5311?
To mitigate CVE-2015-5311, upgrade PowerDNS Authoritative Server to version 3.4.7 or later.
3
What versions are affected by CVE-2015-5311?
CVE-2015-5311 affects PowerDNS Authoritative Server versions 3.4.4, 3.4.5, and 3.4.6.
4
What type of attack does CVE-2015-5311 facilitate?
CVE-2015-5311 allows remote attackers to launch a denial of service attack via crafted query packets.
5
What are the symptoms of CVE-2015-5311 exploitation?
Exploitation of CVE-2015-5311 can result in assertion failures leading to a crash of the PowerDNS server.