CVE-2016-6172: High severity suse linux vulnerability
Published Sep 26, 2016
·Updated
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
Affected Software
3 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
PowerDNS Authoritative Server<=4.0.0
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6172?
CVE-2016-6172 has a severity classification that could lead to denial of service due to memory exhaustion.
2
How do I fix CVE-2016-6172?
To fix CVE-2016-6172, upgrade to PowerDNS Authoritative Server version 4.0.1 or later.
3
What platforms are affected by CVE-2016-6172?
CVE-2016-6172 affects openSUSE Leap 42.1, openSUSE 13.2, and PowerDNS Authoritative Server versions up to 4.0.0.
4
What attack vectors are associated with CVE-2016-6172?
CVE-2016-6172 can be exploited through large AXFR or IXFR responses sent from remote primary DNS servers.
5
What impact does CVE-2016-6172 have on DNS services?
The impact of CVE-2016-6172 includes memory exhaustion and potential crashes of secondary DNS servers.