CVE-2016-5427: High severity powerdns vulnerability
Published Sep 21, 2016
·Updated
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
Affected Software
1 affected component
PowerDNS<=3.4.9
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5427?
CVE-2016-5427 has been assigned a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-5427?
To fix CVE-2016-5427, upgrade PowerDNS Authoritative Server to version 3.4.10 or later.
3
What type of attack does CVE-2016-5427 enable?
CVE-2016-5427 enables remote attackers to cause denial of service through crafted DNS queries.
4
Which versions of PowerDNS are affected by CVE-2016-5427?
PowerDNS Authoritative Server versions prior to 3.4.10, specifically up to version 3.4.9, are affected by CVE-2016-5427.
5
Is CVE-2016-5427 a local or remote vulnerability?
CVE-2016-5427 is a remote vulnerability that can be exploited by sending malicious DNS queries.