CVE-2016-2120: Integer Overflow
An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending a DNS query for that record. The issue is due to an integer overflow when checking if the content of the record matches the expected size, allowing an attacker to cause a read past the buffer boundary.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-2120?
CVE-2016-2120 is an issue found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 that allows an authorized user to crash the server by inserting a specially crafted record in a zone under their control.
What is the severity of CVE-2016-2120?
The severity of CVE-2016-2120 is high with a CVSS score of 6.5.
Which software versions are affected by CVE-2016-2120?
PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 are affected by CVE-2016-2120.
How can CVE-2016-2120 be fixed?
To fix CVE-2016-2120, users should update their PowerDNS Authoritative Server to version 4.1.6-3+deb10u1 or later.
Where can I find more information about CVE-2016-2120?
More information about CVE-2016-2120 can be found at the following references: [PowerDNS Advisory](https://doc.powerdns.com/md/security/powerdns-advisory-2016-05/), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2016-2120), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2120).