CVE-2015-5470: High severity powerdns vulnerability
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5470?
CVE-2015-5470 has a severity rating that indicates it can lead to denial of service attacks, affecting CPU consumption and stability.
How do I fix CVE-2015-5470?
To mitigate CVE-2015-5470, upgrade PowerDNS Recursor to version 3.6.4 or higher and the Authoritative Server to version 3.4.5 or higher.
Which versions of PowerDNS are affected by CVE-2015-5470?
CVE-2015-5470 affects PowerDNS Recursor versions before 3.6.4 and 3.7.x before 3.7.3, as well as Authoritative versions before 3.3.3 and 3.4.x before 3.4.5.
What type of attack does CVE-2015-5470 enable?
CVE-2015-5470 enables remote attackers to launch denial of service attacks by causing high CPU consumption or crashes through specific DNS name requests.
Is there a workaround for CVE-2015-5470 if I can't upgrade?
There are no documented workarounds for CVE-2015-5470, so upgrading to a patched version is the recommended approach.