The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pdns-recursorUpgrade pdns | Jul 30, 2024 | May 18, 2015 |
| Freebsd | — | Upgrade powerdns-recursorUpgrade powerdns | Dec 10, 2025 | May 1, 2015 |
| Suse | — | Upgrade pdns-recursor-debuginfoUpgrade pdns-recursorUpgrade pdns-recursor-debugsource | Dec 18, 2015 | May 18, 2015 |
| Ubuntu | — | Upgrade pdnsUpgrade pdns-recursor | Nov 19, 2024 | May 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub