PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://doc.powerdns.com/md/security/powerdns-advisory-2014-02/ | third party advisory |
http://www.debian.org/security/2014/dsa-3096 | third party advisory vendor advisory |
http://www.securitytracker.com/id/1031310 | vdb entry third party advisory |
http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html | third party advisory |
http://www.securityfocus.com/bid/71545 | vdb entry third party advisory |
http://www.kb.cert.org/vuls/id/264212 | third party advisory us government resource |