CVE-2017-15120: Debian Linux

High severity, CVSS 7.5. EPSS: 51.4% chance of exploitation in the next 30 days.

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a denial of service.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Powerdns Recursor: before 4.0.8 (fixed in 4.0.8)

Published 2018-07-27. Last modified 2026-06-17.