CVE-2015-5470: Powerdns Authoritative
High severity, CVSS 7.8. EPSS: 11.3% chance of exploitation in the next 30 days.
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.
Affected products
- Powerdns Authoritative: up to and including 3.3.2; version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; version 3.4.3 only; version 3.4.4 only
- Powerdns Recursor: up to and including 3.6.3; version 3.7.1 only; version 3.7.2 only
Published 2015-11-02. Last modified 2026-06-17.