Candidate: CVE-2014-8601 PublicDate: 2014-12-10 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8601 http://doc.powerdns.com/md/security/powerdns-advisory-2014-02/ http://www.securitytracker.com/id/1031310 Description: PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_pdns-recursor: upstream_pdns-recursor: released (3.6.2-1) lucid_pdns-recursor: ignored (reached end-of-life) precise_pdns-recursor: ignored (reached end-of-life) precise/esm_pdns-recursor: DNE (precise was needed) trusty_pdns-recursor: released (3.5.3-1ubuntu0.1) trusty/esm_pdns-recursor: DNE (trusty was released [3.5.3-1ubuntu0.1]) utopic_pdns-recursor: ignored (reached end-of-life) vivid_pdns-recursor: not-affected (3.6.2-2) vivid/stable-phone-overlay_pdns-recursor: DNE vivid/ubuntu-core_pdns-recursor: DNE wily_pdns-recursor: not-affected (3.6.2-2) xenial_pdns-recursor: not-affected (3.6.2-2) yakkety_pdns-recursor: not-affected (3.6.2-2) zesty_pdns-recursor: not-affected (3.6.2-2) devel_pdns-recursor: not-affected (3.6.2-2)