CVE-2016-5426: High severity powerdns vulnerability
Published Sep 21, 2016
·Updated
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
Affected Software
1 affected component
PowerDNS<=3.4.9
Remediation
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5426?
CVE-2016-5426 has a medium severity rating as it can lead to denial of service by consuming backend CPU resources.
2
How does CVE-2016-5426 affect PowerDNS?
CVE-2016-5426 allows remote attackers to exploit PowerDNS by sending a specially crafted long qname, causing high CPU consumption.
3
How do I fix CVE-2016-5426?
To fix CVE-2016-5426, upgrade PowerDNS to version 3.4.10 or later.
4
Which versions of PowerDNS are vulnerable to CVE-2016-5426?
PowerDNS versions prior to 3.4.10, specifically 3.4.9 and earlier, are vulnerable to CVE-2016-5426.
5
What types of attacks does CVE-2016-5426 enable?
CVE-2016-5426 enables denial of service attacks through excessive resource consumption on the backend.