Candidate: CVE-2016-5427 PublicDate: 2016-09-21 14:25:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5427 https://doc.powerdns.com/md/security/powerdns-advisory-2016-01/ Description: PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_pdns: upstream: https://github.com/PowerDNS/pdns/commit/881b5b03a590198d03008e4200dd00cc537712f3 upstream_pdns: released (4.0.0~alpha1-1) precise_pdns: ignored (reached end-of-life) precise/esm_pdns: DNE (precise was needed) trusty_pdns: ignored (reached end-of-life) trusty/esm_pdns: DNE (trusty was needed) vivid/stable-phone-overlay_pdns: DNE vivid/ubuntu-core_pdns: DNE xenial_pdns: not-affected (4.0.0~alpha2-3build1) yakkety_pdns: not-affected zesty_pdns: not-affected artful_pdns: not-affected bionic_pdns: not-affected cosmic_pdns: not-affected disco_pdns: not-affected devel_pdns: not-affected