Description
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- PowerDNS / Recursor0 – 4.9.9
- PowerDNS / Recursor5.0.0 – 5.0.9
- PowerDNS / Recursor5.1.0 – 5.1.2