CVE-2015-1868
Published · Updated
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 82%
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
Affected products
n/a · n/aReferences
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156648.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156655.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156667.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156680.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156725.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156743.htmlhttp://www.debian.org/security/2015/dsa-3306http://www.debian.org/security/2015/dsa-3307http://www.securityfocus.com/bid/74306http://www.securitytracker.com/id/1032220