Candidate: CVE-2016-6172 PublicDate: 2016-09-26 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6172 http://www.openwall.com/lists/oss-security/2016/07/06/4 Description: PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response. Ubuntu-Description: Notes: Bugs: https://github.com/PowerDNS/pdns/issues/4128 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H [6.8 MEDIUM] Patches_pdns: upstream_pdns: released (4.0.1-1) precise_pdns: ignored (reached end-of-life) precise/esm_pdns: DNE (precise was needs-triage) trusty_pdns: ignored (reached end-of-life) trusty/esm_pdns: DNE (trusty was needed) vivid/stable-phone-overlay_pdns: DNE vivid/ubuntu-core_pdns: DNE wily_pdns: ignored (reached end-of-life) xenial_pdns: ignored (end of standard support, was needed) yakkety_pdns: ignored (reached end-of-life) zesty_pdns: ignored (reached end-of-life) artful_pdns: ignored (reached end-of-life) bionic_pdns: not-affected (4.0.1-1) cosmic_pdns: not-affected (4.0.1-1) disco_pdns: not-affected (4.0.1-1) eoan_pdns: not-affected (4.0.1-1) focal_pdns: not-affected (4.0.1-1) groovy_pdns: not-affected (4.0.1-1) hirsute_pdns: not-affected (4.0.1-1) impish_pdns: not-affected (4.0.1-1) jammy_pdns: not-affected (4.0.1-1) devel_pdns: not-affected (4.0.1-1)