CVE-2016-6172

MEDIUM

PowerDNS <4.0.1 - DoS

Title source: llm

Description

PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.

Scores

CVSS v3 6.8
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Classification

CWE
CWE-400
Status published

Affected Products (4)

opensuse/leap
opensuse/opensuse
powerdns/authoritative_server < 4.0.0
n/a/n/a

Timeline

Published Sep 26, 2016
Tracked Since Feb 18, 2026